Analysis · curated 14 Jul 2026

Malicious MCP Servers & Email Security: The New Supply Chain Threat

Coverage timeline

9 Jun 2026powerdmarc.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

The postmark-mcp case is described as the first documented in-the-wild malicious MCP server breach, showing how AI agent supply-chain compromises can exfiltrate sensitive email at scale while bypassing traditional authentication controls.

The article analyzes the postmark-mcp incident, where a malicious actor published an exact-name lookalike npm package impersonating Postmark's official Model Context Protocol (MCP) server. Across 15 clean releases it built trust before adding a hidden BCC rule that silently forwarded 3,000-15,000 corporate emails per day to an attacker-controlled domain, leaking passwords, invoices, customer data, and auth tokens; because mail flowed through legitimate infrastructure, SPF and DKIM passed automatically.