postmark-mcp
Disclosed Sep 25, 20251 year agoUnverified
First malicious MCP server on npm secretly BCC'd every email to attacker
An unofficial npm copy of the Postmark MCP server, which lets AI assistants send email, added one line in version 1.0.16 that BCC'd every sent email to an attacker-controlled address; it was downloaded about 1,500 times before removal, and Koi Security estimated thousands of emails were exfiltrated.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 25, 2025 |
| Attack | Supply chain |
| Data exposed | Emails, Messages, Credentials and tokens |
| Sector | Tech |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Packagethehackernews.com · News | News |
| Unofficial Postmark MCP npm silently stole users' emailsbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 25, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.