A malicious MCP server stole emails via a hidden BCC in postmark-mcp
Blog post from MintMCP
In September 2025, researchers disclosed a malicious npm package, postmark-mcp, believed to be the first harmful Model Context Protocol server found in the wild, which secretly BCCed emails sent through AI-powered Postmark workflows to an attacker-controlled address. The package reportedly built trust through normal use before a later update added the minimal exfiltration code, enabling the theft of sensitive material such as invoices, password resets, customer correspondence, and internal messages without compromising Postmark itself. The incident was a supply-chain attack rather than a prompt-injection or model-safety failure, exploiting MCP servers’ position as highly trusted middleware with access to agent instructions, credentials, sensitive content, and external services. Because the backdoor used the ordinary email delivery path, workflows continued to function normally and logs showed no obvious warning signs. The case illustrates how broadly privileged AI connectors can create a large blast radius when compromised, especially when agents link services such as email, CRM, billing, and support systems.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 24 | 7,956 | 795 | 196 | +24% |
| Secrets Management | 3 | 1,971 | 393 | 127 | +1% |
| AI Agents | 1 | 5,835 | 1,407 | 272 | -21% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.