Why the hell doesn't the article say WHICH plugins were affected so users can know if they were likely affected?
> It enables malicious versions of legitimate Obsidian plugins ('Shell Commands' and 'Hider') that are present in the shared vault.
1. Plugins are stored inside your vault.
2. If you open a vault from an untrusted source, it could contain custom/malicious plugins that will run things on your computer.
3. Then end.