Chronicle/Attacks & incidents

Malicious postmark-mcp npm package quietly copied every sent email to an outside address

AttackIncidentSignificance assistant-drafted

A package impersonating a Postmark email MCP server was published to npm and, after 15 clean versions, version 1.0.16 (2025-09-17) added code that blind-copied all emails sent through it to the publisher. Postmark stated it had never published an MCP server on npm; Koi Security found it, and the package was deleted after about 1,643 downloads.

Why it matters

Koi Security, which found it, called it the first malicious MCP server seen in the wild, showing that MCP packages are already a live supply-chain target.

Key facts

As stated in the sources, with where to find them.

  • Malicious behavior began in version 1.0.16, released 2025-09-17.The Hacker News article body
  • The package had 1,643 downloads before removal.The Hacker News article body

Findings that cite this record

Key questions this bears on

Sources

Related records