Malicious MCP Server on npm postmark-mcp Harvests Emails
CYBERSECURITY FEATURED ANALYSIS

Malicious MCP Server on npm postmark-mcp Harvests Emails

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

Urgent security alert: On September 25, 2025, the npm package ‘postmark-mcp’ was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, …

Urgent security alert: On September 25, 2025, the npm package ‘postmark-mcp’ was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, including uninstalling, rotating credentials, and scanning with Snyk’s MCP-Scan.