Threat

Malicious MCP Server on npm postmark-mcp Harvests Emails

Page published · Page updated

Dossier

Earliest dated coverage: 25 Sep 2025 · First observed: 9 Oct 2026 · Latest dated coverage: 25 Sep 2025

Coverage timeline

discovered snyk.io primary 25 Sep 2025nhimg.org

Single-source incident — one report is available.

Why it matters

postmark-mcp shows that installing an MCP server grants a stranger the same delegated credentials and broad access as your AI agent, turning a trusted connector into a silent data-exfiltration channel.

Koi Security discovered that the npm package postmark-mcp, a lookalike of Postmark's official MCP server, added a single line in version 1.0.16 (17 Sep 2025) that blind-copied every email an AI agent sent to an attacker-controlled address at giftshop[.]club. The package had 1,643 downloads before removal; Postmark said it was unaffiliated and its own services were not affected, while researchers called it the first real-world sighting of a malicious MCP server.

campaign

Summary

In September 2025, researchers found that the npm package postmark-mcp, which posed as a Model Context Protocol (MCP) server for the Postmark transactional email service, had been quietly copying every email it sent to an attacker-controlled address. The package let AI assistants send email through a user's Postmark account, and its first fifteen versions behaved as advertised.[0][2]

Version 1.0.16, released on 17 September 2025, added a single line that blind-copied each outgoing message to phan@giftshop.club, exfiltrating the email through the victim's own Postmark credentials so the theft blended into legitimate traffic. Snyk's diff of versions 1.0.15 and 1.0.18 confirmed that BCC line was the only notable change.[0][2]

Postmark, which had no connection to the package, published a warning on 25 September 2025 stating its API and services were unaffected and advising users to remove the package, review email logs, and rotate credentials. Koi Security described it as the first real-world sighting of a malicious MCP server; its estimates of hundreds of affected organisations are the researcher's own, while Postmark knew of only one customer that used it.[0][2]

Attack chain

  1. Impersonation: The attacker copied Postmark's open-source MCP server (published on GitHub, not npm) and republished it on npm under the trusted-sounding name postmark-mcp, where Postmark had no official package.[0][2]
  2. Trust building: Fifteen clean, functional versions were released so the package accumulated users and appeared legitimate.[0]
  3. Credential inheritance: Users configured the server with their own Postmark credentials and allowed their AI assistants to send email through it, granting the tool the agent's delegated access.[0]
  4. Weaponization: Version 1.0.16 added a single line that blind-copied every outgoing message to phan@giftshop.club, sent through the victim's own Postmark account and invisible in the agent's response.[0][2]
  5. Persistence after takedown: When exposed, the developer deleted the package from npm, but already-installed copies kept forwarding email until users manually removed them.[0]

Disclosure timeline

DateEvent
2025-09-15postmark-mcp version 1.0.0 is first published to npm by the account 'phanpak'.[0][2]
2025-09-17Version 1.0.16 adds the hidden BCC to phan@giftshop.club; later versions up to 1.0.18 retain it.[0][2]
2025-09-25Postmark and Snyk publish warnings; the package no longer appears on npm.[0][2]
2025-09-26CSO Online reports Koi Security's findings and scale estimates.[0]
2025-09-29The Hacker News and The Register report the incident.[0]

Actor profile

phanpak (npm account)

The malicious package was published from the npm account 'phanpak', which maintains 31 other packages. The account is not linked to any known threat group. The operator demonstrated supply-chain tradecraft: cloning a legitimate open-source MCP server, building reputation across fifteen clean releases, then quietly inserting a one-line BCC backdoor before deleting the package once detected.[0]

How it works

The backdoor was not a software vulnerability but a deliberate trojanization of a cloned MCP server. The send-email tool in index.js was altered to add 'Bcc: phan@giftshop.club' (with ReplyTo set to the sender or default sender), causing every message sent through the tool to be silently copied to the attacker. Because the MCP server runs with the agent's delegated privileges and uses the victim's own Postmark server token, the exfiltration occurred within legitimate, authenticated traffic, making it difficult to detect from logs alone. Exposed data included message content, attachments, and headers, which may contain secrets, tokens, and personal or regulated data.[0][2]

Affected versions and patch status

ProductAffectedPatch status
postmark-mcp (unofficial npm package impersonating Postmark's MCP server)Versions 1.0.16 through 1.0.18 contained the malicious BCC; versions 1.0.0–1.0.15 were benign.Package deleted from npm by the developer; already-installed copies remain active until manually removed. Users should switch to Postmark's official MCP server from its GitHub repository.[0][2]

Indicators of Compromise

TypeIndicatorContext
emailphan@giftshop.clubHardcoded BCC recipient address that received exfiltrated copies of every email sent through the malicious postmark-mcp tool.[2]
domaingiftshop.clubAttacker-controlled domain hosting the BCC exfiltration address; defenders are advised to block it and check email logs for BCC traffic to it.[0][2]
othernpm package postmark-mcp (versions 1.0.16–1.0.18)Malicious npm package impersonating Postmark's MCP server; the named versions contain the email-exfiltration backdoor.[0][2]
othernpm account: phanpakPublisher account that released the malicious postmark-mcp package and maintains 31 other packages.[0]

Key takeaways

  • An MCP server is a non-human identity that acts with the agent's delegated credentials; installing one effectively grants its author the same access as your agent, so each tool must be vetted, scoped, and monitored like any other identity.[0]
  • A single added line of code in a trusted-looking supply-chain package was enough to exfiltrate thousands of emails through victims' own legitimate credentials, demonstrating that version pinning and change review are essential before upgrading agent tooling.[0][2]

Defensive actions

  • Remove postmark-mcp and rotate affected credentials.: Uninstalling the package stops ongoing exfiltration; rotating Postmark API and SMTP credentials plus any secrets sent by email during the compromise period limits reuse of stolen data.[0][2]
  • Block the giftshop.club domain and review email logs for unexpected BCC recipients.: The backdoor forwarded mail to phan@giftshop.club through victims' own accounts, so blocking the domain and auditing logs for hidden BCC traffic detects and contains the leak.[0][2]
  • Install MCP servers only from the publisher's official source and pin reviewed versions.: The attack relied on a look-alike npm package where Postmark had no official listing; verifying provenance and reviewing version changes before upgrading would have caught the single malicious line.[0]
  • Give each MCP server its own narrowly scoped credential and maintain an inventory of agent tools.: An MCP server acts with the agent's delegated credentials, so scoped tokens and tool inventories limit the blast radius of a malicious server and improve discoverability.[0]