Sev0AI security incidents, tracked

All incidents / Supply chain and access

First malicious MCP server found secretly copying every email to an attacker

postmark-mcp users, disclosed 25 Sep 2025. Supply chain and access Data exposed High

A fake postmark-mcp package on npm, used to let AI assistants send email, added a hidden BCC to every message it sent, forwarding password resets, invoices and internal mail to an attacker's address. It was downloaded about 1,600 times before removal.

Disclosed
25 Sep 2025
Organization
postmark-mcp users
Vendor
Any model
Product
postmark-mcp (open source)
Type of AI
AI building block
How it happened
Supply chain and access: Poisoned package
Harm
Data exposed
Data involved
Personal data, Credentials, Internal documents
Reach
Many organizations
Records
1,643
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
  2. https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "First malicious MCP server found secretly copying every email to an attacker", https://sev0.fyi/incidents/2025-09-25-postmark-mcp-malicious-server/