Hacker News new | ask | show | jobs
by kepano 45 days ago
The specific plugins don't matter for this attack. The attack relies on the user accepting a shared vault and trusting the shared plugins. A shared vault can contain plugins that don't come from the official directory.