Analysis · curated 14 Jul 2026
Malicious MCP Servers & Email Security: The New Supply Chain Threat
First reported powerdmarc.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
The postmark-mcp case is described as the first documented in-the-wild malicious MCP server breach, showing how AI agent supply-chain compromises can exfiltrate sensitive email at scale while bypassing traditional authentication controls.
The article analyzes the postmark-mcp incident, where a malicious actor published an exact-name lookalike npm package impersonating Postmark's official Model Context Protocol (MCP) server. Across 15 clean releases it built trust before adding a hidden BCC rule that silently forwarded 3,000-15,000 corporate emails per day to an attacker-controlled domain, leaking passwords, invoices, customer data, and auth tokens; because mail flowed through legitimate infrastructure, SPF and DKIM passed automatically.