MAL-2025-47604postmark-mcp: malicious MCP server copied every email
postmark-mcp 1.0.16 on npm quietly sent a blind copy of every email it handled to an attacker. Koi Security called it the first known malicious MCP server.
What happened
On 25 September 2025 Koi Security reported postmark-mcp, an npm package that worked as an MCP server for sending email through Postmark. Version 1.0.16 added the address phan@giftshop[.]club as a BCC recipient on every email it sent.
Koi described it as the first known malicious MCP server on npm. Postmark published a notice about the package, and it is tracked as MAL-2025-47604.
Why it worked
An MCP server runs with whatever access you hand it, in this case email content and the ability to send mail. If updates are installed without reading the diff, a changed version runs with the same trust as the one you originally vetted.
What to do
- Pin MCP server packages to exact versions and review the diff before updating.
- Prefer servers published by the vendor of the service they connect to.
- Restrict each MCP server's outbound network to the API it needs.
- Check outgoing mail logs for unexpected BCC recipients.
Vet skills, plugins and MCP serversRestrict outbound network access
OpenClaw Control UI leaked gateway tokens for one-click RCE
Amazon Q Developer extension shipped with a wiper prompt
Work through the security checklist →