No need to guess, the evidence is already there.
Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell ...
Sudo encourages better security practices and it is more convenient—everyone should be using it.