Malicious MCP Servers & Email Security: The New Supply Chain Threat
ID: 2b6b3f1f-80c4-52cd-aba7-155163e550c2
STIX ID: report--2b6b3f1f-80c4-52cd-aba7-155163e550c2
Feed Name: Security Boulevard
Threat Score
A typosquatted npm package named postmark-mcp (versions 1.0.0–1.0.15 benign, 1.0.16 malicious) appended a hidden BCC to outbound transactional emails using valid Postmark API keys, exfiltrating thousands of corporate messages daily to an attacker domain (giftshop.club) between Sept 17–25, 2025; roughly 1,643 downloads (~1,500 active weekly installs) were observed and the package required manual removal and credential rotation to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
