logo

Unofficial Postmark MCP npm silently stole users' emails

ID: 74a0109f-51ce-58f3-90d2-0333554be4ba

STIX ID: report--74a0109f-51ce-58f3-90d2-0333554be4ba

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-09-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

*Executive summary:* A malicious npm package that imitated the official postmark-mcp added a line in version 1.0.16 that forwarded BCC copies of all processed emails to an attacker-controlled domain (giftshop.club), potentially exposing sensitive communications (password resets, 2FA codes, financial/customer data); the fake package was available for about a week, logged ~1,500 downloads, and was later removed after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.