• News/
  • https://www.theregister.com/2025/09/29/postmark_mcp_server_code_hijacked/

Fake Postmark MCP npm package stole emails with one-liner

The Register
·
Jessica Lyons
·
Published Sep 29, 2025
·
Updated

A fake npm package posing as Postmark's MCP (Model Context Protocol) server silently stole potentially thousands of emails a day by adding a single line of code that secretly copied outgoing messages to an attacker-controlled address. In a blog post late last week, Postmark warned users about "postmark-mcp" on npm impersonating the email delivery service and stealing its users' emails. "We want to be crystal clear: Postmark had absolutely nothing to do with this package or the malicious activity," the company said on September 25. "Here's what happened: A malicious actor created a fake package on npm impersonating our name, built trust over 15 versions, then added a backdoor in version 1.0.16 that secretly BCC'd emails to an external server." If you downloaded the fake package, Postmark recommends immediately removing it, checking email logs for suspicious activity, and rotating any credentials sent via email. While we don't know how many organizations were affected by this security incident, Postmark boasts "thousands" of customers, including Ikea, Asana, Minecraft, and 1Password, on its website. However, the company told The Register after publication that it knows of only one Postmark customer that actually used the affected package, and that its own systems were not breached and remain secure. Koi Security, which discovered the malicious package, says it was downloaded about 1,500 times in a week, integrated into hundreds of developer workflows, and likely stole thousands...

Read full article

Affected Software

1 affected component
npm postmark-mcp=1.0.16
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security breach involving a fake npm package for Postmark's MCP server that stole emails.

2

What security implications are discussed in the article?

The article highlights the risk of using malicious npm packages that can lead to the theft of sensitive information, such as emails.

3

What specific npm package is mentioned as being compromised?

The compromised package is identified as the fake 'postmark-mcp' npm package.

4

How did the fake package operate to steal emails?

The fake package operated by adding a single line of code that redirected outgoing messages to an attacker-controlled address.

5

What version of the affected package is mentioned in the article?

The affected version of the npm package is 1.0.16.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203