Unofficial Postmark MCP npm silently stole users' emails
ID: 74a0109f-51ce-58f3-90d2-0333554be4ba
STIX ID: report--74a0109f-51ce-58f3-90d2-0333554be4ba
Feed Name: Bleeping Computer
Threat Score
*Executive summary:* A malicious npm package that imitated the official postmark-mcp added a line in version 1.0.16 that forwarded BCC copies of all processed emails to an attacker-controlled domain (giftshop.club), potentially exposing sensitive communications (password resets, 2FA codes, financial/customer data); the fake package was available for about a week, logged ~1,500 downloads, and was later removed after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
