New Ghost Campaign Uses Fake npm Progress Bars to Phish Sudo Passwords

2026-03-27T08:51:45Za43499b001122b7bbe222f71a4070bfd6b9179760d0f3344a557d983480519ac
DKIMDMARCIoTMiraiPXA stealerQR code phishingSPFaccount takeoverbotnetcrypto wallet theftdeveloper securitymalwarenpmnpm malicious packagesphishingsudo credential theftsupply chaintelegram exfiltration

What happened

Multiple recent threats targeting developers and organizations: ReversingLabs uncovered a 'Ghost' phishing campaign that fakes npm install logs/progress bars to trick developers into entering sudo passwords and steal crypto wallets. Related reporting highlights hijacked npm developer accounts pushing malware to steal API keys/passwords, a large QR‑code phishing campaign (1.6M recipients) that evaded SPF/DKIM/DMARC, a rise in PXA Stealer attacks against financial firms that use Telegram for exfiltration, and accelerating Mirai botnet variant growth impacting IoT. These issues elevate supply‑and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
a43499b001122b7bbe222f71a4070bfd6b9179760d0f3344a557d983480519ac
Enrichment time
2026-03-27T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.