Skip to content

postmark-mcp

Disclosed Sep 25, 20251 year agoUnverified

First malicious MCP server on npm secretly BCC'd every email to attacker

An unofficial npm copy of the Postmark MCP server, which lets AI assistants send email, added one line in version 1.0.16 that BCC'd every sent email to an attacker-controlled address; it was downloaded about 1,500 times before removal, and Koi Security estimated thousands of emails were exfiltrated.

What is known

People affectedNot stated in the sources we have
DisclosedSep 25, 2025
AttackSupply chain
Data exposedEmails, Messages, Credentials and tokens
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalSep 25, 2025
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about postmark-mcp

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.