New Ghost Campaign Uses Fake npm Progress Bars to Phish Sudo Passwords
2026-03-27T08:51:45Z•a43499b001122b7bbe222f71a4070bfd6b9179760d0f3344a557d983480519ac
DKIMDMARCIoTMiraiPXA stealerQR code phishingSPFaccount takeoverbotnetcrypto wallet theftdeveloper securitymalwarenpmnpm malicious packagesphishingsudo credential theftsupply chaintelegram exfiltration
What happened
Multiple recent threats targeting developers and organizations: ReversingLabs uncovered a 'Ghost' phishing campaign that fakes npm install logs/progress bars to trick developers into entering sudo passwords and steal crypto wallets. Related reporting highlights hijacked npm developer accounts pushing malware to steal API keys/passwords, a large QR‑code phishing campaign (1.6M recipients) that evaded SPF/DKIM/DMARC, a rise in PXA Stealer attacks against financial firms that use Telegram for exfiltration, and accelerating Mirai botnet variant growth impacting IoT. These issues elevate supply‑and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- a43499b001122b7bbe222f71a4070bfd6b9179760d0f3344a557d983480519ac
- Enrichment time
- 2026-03-27T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.