dotsagent.io
Language:English
MAL-2025-47604

postmark-mcp: malicious MCP server copied every email

postmark-mcp 1.0.16 on npm quietly sent a blind copy of every email it handled to an attacker. Koi Security called it the first known malicious MCP server.

What happened

On 25 September 2025 Koi Security reported postmark-mcp, an npm package that worked as an MCP server for sending email through Postmark. Version 1.0.16 added the address phan@giftshop[.]club as a BCC recipient on every email it sent.

Koi described it as the first known malicious MCP server on npm. Postmark published a notice about the package, and it is tracked as MAL-2025-47604.

Why it worked

An MCP server runs with whatever access you hand it, in this case email content and the ability to send mail. If updates are installed without reading the diff, a changed version runs with the same trust as the one you originally vetted.

What to do

  • Pin MCP server packages to exact versions and review the diff before updating.
  • Prefer servers published by the vendor of the service they connect to.
  • Restrict each MCP server's outbound network to the API it needs.
  • Check outgoing mail logs for unexpected BCC recipients.

Vet skills, plugins and MCP serversRestrict outbound network access

Work through the security checklist →

Sources

  1. koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-theft
  2. postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026