BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

First Malicious MCP Server Found in npm Postmark-MCP Package

Malicious npm Package postmark-mcp Steals Emails via Malicious MCP Server Discovered in Supply Chain Attack

  • Security researchers detected the first known malicious Model Context Protocol (MCP) server in the wild on September 17, 2025.
  • A fake npm package named postmark-mcp imitating a legitimate library was found to steal emails by copying them to an external server.
  • The compromised package was uploaded by developer phanpak, was downloaded over 1,600 times, and later removed from the npm repository.
  • The attack added a BCC line forwarding emails to “phan@giftshop[.]club,” exposing sensitive communications.
  • Developers using this package are advised to remove it, change exposed credentials, and check for unauthorized email forwarding.

On September 17, 2025, Cybersecurity researchers uncovered the first real-world case of a malicious Model Context Protocol (MCP) server embedded in an npm package called postmark-mcp. The package, uploaded by developer phanpak, copied emails sent through the MCP service to a personal server without user consent, creating significant supply chain risks.

- Advertisement -

The MCP server is intended to help users send emails, manage templates, and track campaigns using AI assistants. The legitimate library is available on GitHub and can be accessed through Postmark Labs. However, version 1.0.16 of the npm clone, released on September 17, 2025, included a malicious change that silently forwarded all emails to “phan@giftshop[.]club” by adding a blind carbon copy (BCC).

Phanpak uploaded the fake package on September 15, 2025, and it attracted around 1,643 downloads before being removed from the npm repository. Koi Security CTO Idan Dardikman stated, “Since version 1.0.16, it’s been quietly copying every email to the developer’s personal server.” He emphasized the simplicity of the backdoor and the broad impact it could have by stealing thousands of emails.

MCP servers operate with high trust and permissions inside development toolchains, handling sensitive data like password resets and customer communications. Security company Snyk noted that the backdoor was designed specifically to harvest emails from agentic workflows relying on the MCP server. They highlighted the risks involved due to the elevated privileges and data sensitivity managed by MCP servers.

Developers who installed the compromised package are advised to remove postmark-mcp from their projects immediately. They should rotate any credentials that might have been exposed and review email logs for any unauthorized BCC to the reported domain. This incident illustrates ongoing threats from malicious actors exploiting trust within open-source and emerging ecosystems.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Starcloud mining Bitcoin in space is a really crazy $2B idea

Starcloud, a data centers-in-space startup, raised nearly $500 million at a $2 billion valuation...

EIP-8141 Frames: Pay Gas in Tokens on Ethereum

EIP-8141's Frame transactions split a transaction into validation, payment and execution steps, each an...

Zcash ETF launch sparks rally to 2016 high

ZCash (ZEC) surged to $1,249.28, its highest price since 2016, pushing market cap above...

JSCeal Malware Steals Crypto via Compiled V8 Bytecode

Cybersecurity researchers have unveiled JSCeal, a sophisticated compiled V8 JavaScript malware used to steal...

Fomo overtakes Pump.fun in daily revenue on Solana

Social trading platform Fomo generated $1.76 million in daily revenue on Friday, surpassing memecoin...

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading