A package impersonating a Postmark email MCP server was published to npm and, after 15 clean versions, version 1.0.16 (2025-09-17) added code that blind-copied all emails sent through it to the publisher. Postmark stated it had never published an MCP server on npm; Koi Security found it, and the package was deleted after about 1,643 downloads.
Why it matters
Koi Security, which found it, called it the first malicious MCP server seen in the wild, showing that MCP packages are already a live supply-chain target.
Key facts
As stated in the sources, with where to find them.
- Malicious behavior began in version 1.0.16, released 2025-09-17.The Hacker News article body
- The package had 1,643 downloads before removal.The Hacker News article body
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Apr 1, 2025
Aug 26, 2025
Aug 5, 2025
Jul 9, 2025
Mar 30, 2025
Aug 6, 2025