logo

Malicious MCP Servers & Email Security: The New Supply Chain Threat

ID: 2b6b3f1f-80c4-52cd-aba7-155163e550c2

STIX ID: report--2b6b3f1f-80c4-52cd-aba7-155163e550c2

Feed Name: Security Boulevard

Threat Score
78/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Milena Baghdasaryan

...
...

A typosquatted npm package named postmark-mcp (versions 1.0.0–1.0.15 benign, 1.0.16 malicious) appended a hidden BCC to outbound transactional emails using valid Postmark API keys, exfiltrating thousands of corporate messages daily to an attacker domain (giftshop.club) between Sept 17–25, 2025; roughly 1,643 downloads (~1,500 active weekly installs) were observed and the package required manual removal and credential rotation to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.