Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

So the first malicious MCP server has been found on npm, what does this mean for MCP security?

Blog post from Semgrep

Post Details
Company
Date Published
Author
Katie Paxton-Fear
Word Count
1,509
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent discovery by Koi research revealed a subtle attack on npm involving a malicious MCP server named postmark-mcp, which added a BCC line to emails sent through an AI agent, allowing an attacker to receive copies. This incident raises questions about the security of Model-Context-Protocol (MCP) servers, which act as interfaces for AI agents interacting with traditional software. Although MCP is designed to be simple, this simplicity can create vulnerabilities, as seen in this attack where an attacker used typosquatting on npm to exploit the system. The incident emphasizes the need for robust security practices in MCP development, such as input validation, authentication, and supply chain security, as AI becomes more integrated into software systems. It also highlights the ongoing challenge of balancing AI advancements with security measures, suggesting a future shift towards trusted MCP marketplaces and potentially adopting zero trust principles for AI agents to prevent similar attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 38 4,861 352 133 +57%
AI Agents 6 3,102 615 183 +29%
AI Coding Assistant 1 967 193 90 -7%
Vector Search 1 1,589 336 137 +6%
Zero Trust 1 91 23 19 -19%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.