Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Malicious MCP Server on npm postmark-mcp Harvests Emails

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal
Word Count
3,282
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

In September 2025, the npm package "postmark-mcp," designed for AI assistants to send emails via the Postmark service, was discovered to have been maliciously modified to exfiltrate email contents by blind-copying them to an external domain. This security breach, which likely started with version 1.0.16, highlights a significant supply chain security incident involving an MCP (Model Context Protocol) server. The backdoor was intended to harvest emails sent through the server, potentially compromising sensitive data like passwords, customer information, and internal communications. Users who installed the package from mid-September 2025 are advised to uninstall it, rotate credentials, review email logs, and block the associated domain to mitigate risks. The incident underscores the need for vigilance in monitoring and managing third-party packages, especially those with high trust and broad permissions in agent toolchains.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 55 3,632 330 137 -26%
Secrets Management 1 1,095 203 86 -9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.