First malicious MCP server found secretly copying every email to an attacker
A fake postmark-mcp package on npm, used to let AI assistants send email, added a hidden BCC to every message it sent, forwarding password resets, invoices and internal mail to an attacker's address. It was downloaded about 1,600 times before removal.
- Disclosed
- 25 Sep 2025
- Organization
- postmark-mcp users
- Vendor
- Any model
- Product
- postmark-mcp (open source)
- Type of AI
- AI building block
- How it happened
- Supply chain and access: Poisoned package
- Harm
- Data exposed
- Data involved
- Personal data, Credentials, Internal documents
- Reach
- Many organizations
- Records
- 1,643
- Severity
- High
- Model at fault
- No
- Status
- Confirmed