κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package
άμυνα
.

First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package

29/09/2025

Sep 29, 2025Ravie LakshmananMCP Server / Vulnerability
Cybersecurity researchers have discovered what has been described as the first-ever instance of a Model Context Protocol (MCP) server spotted in the wild, raising software supply chain risks.
According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called “postmark-mcp” that copied an official Postmark Labs library of the same name. The malicious functionality was introduced in version 1.0.16, which was released on September 17, 2025.
The actual “postmark-mcp” library, available on GitHub, exposes an MCP server to allow users to send emails, access and use email templates, and track campaigns using artificial intelligence (AI) assistants.

The npm package in question has since been deleted from npm by the developer “phanpak,” who uploaded it to the repository on September 15, 2025, and maintains 31 other packages. The JavaScript library attracted a total of 1,643 downloads.
“Since version 1.0.16, it’s been quietly copying every email to the developer’s personal server,” Koi Security Chief Technology Officer Idan Dardikman said. “This is the world’s first sighting of a real-world malicious MCP server. The attack surface for endpoint supply chain attacks is slowly becoming the enterprise’s biggest attack surface.”

The malicious package is a replica of the original library, save for a one-line change added in version 1.0.16 that essentially forwards every email sent using the MCP server to the email address “phan@giftshop[.]club” by BCC’ing it, potentially exposing sensitive communications.
“The postmark-mcp backdoor isn’t sophisticated – it’s embarrassingly simple,” Dardikman said. “But it perfectly demonstrates how completely broken this whole setup is. One developer. One line of code. Thousands upon thousands of stolen emails.”
Developers who have installed the npm package are recommended to immediately remove it from their workflows, rotate any credentials that may have been exposed through email, and review email logs for BCC traffic to the reported domain.

“MCP servers typically run with high trust and broad permissions inside agent toolchains. As such, any data they handle can be sensitive (password resets, invoices, customer communications, internal memos, etc.),” Snyk said. “In this case, the backdoor in this MCP Server was built with the intention to harvest and exfiltrate emails for agentic workflows that relied on this MCP Server.”
The findings illustrate how threat actors continue to abuse the user trust associated with the open-source ecosystem and the nascent MCP ecosystem to their advantage, especially when they are rolled out in business critical environments without adequate guardrails.

Source: thehackernews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-2

Your RAM has more than one XMP profile, and here's when to use the others

Enabling XMP or EXPO in the motherboard's BIOS is one of the first things all enthusiasts do after building a new PC. It's an easy way to ensure that you're getting the RAM speed you paid for, and often times doesn't compromise stability. They stand for eXtreme Memory Profile and Extended Profiles for Overclocking, and are different flavors of RAM overclocking validation for Intel and AMD, … [Read More...]

Ditching smart home subscriptions for open-source Home Assistant

I quickly grew tired of having countless smart home subscriptions to create the ultimate tech-laden household. And it's not just the usual suspects, like an alarm system, network switches, or some bulbs requiring cloud support plans. Almost everything you can purchase for the "smart home" can come packing some advanced features that require some sort of recurring fee. Like media subscriptions such … [Read More...]

I migrated my cloud photos to my self-hosted Immich, here's how

Like most people, I've been on the Google Photos bandwagon for years now. Photos of trips, birthdays, receipts, and random food snaps have all been backed up to Google Photos. Initially, it was free and convenient as an add-on perk with my Pixel phone. Over time, I ran into the same problems as everyone else. While the perk disappeared, I was locked in, and my growing library pushed me towards … [Read More...]

I replaced Adobe Premiere with DaVinci Resolve, and I'm not missing out on anything

Leaving my Adobe subscriptions behind felt like a gamble at first. Some tools were easy to replace, especially since there are so many great open-source graphics apps out there. But some were harder to replace – finding a decent alternative for After Effects felt like it took forever. And then there was also Premiere Pro. Source: xda-developers.com … [Read More...]

You have to play these Mario games before the Super Mario Galaxy Movie comes out in 2026

Nintendo announced the sequel to The Super Mario Bros. Movie will be hitting theaters on April 3, 2026. The follow-up is titled The Super Mario Galaxy Movie, and was revealed during the Sepember 2025 Nintendo Direct Presentation as part of the celebration of the 40th anniversary of the Super Mario series. To commemorate the occasion, Nintendo is releasing multiple Mario games for the Nintendo … [Read More...]

This week’s best deal is a ‘kids’ Kindle Paperwhite that’s better than the adult version

Our other favorite deals from this week include refurbished Sonos gear and the 8BitDo Ultimate 2 controller.Oct 4, 2025, 5:00 PM UTCSheena Vasani writes about tech news, reviews gadgets, and helps readers save money by highlighting deals and product recommendations for The Verge.Amazon’s Prime Big Deal Days may bring some great Kindle deals, but if you can’t wait, you don’t have to. Right now, the … [Read More...]

Vicinae is basically Raycast for Linux, and it's (almost) everything I wanted

Recently, I've written quite a bit about Raycast, and how it's my absolute favorite app on macOS, and now on Windows as well, thanks to the recent beta launch. But outside of macOS, I'm more of a Linux user these days, and I recently expressed my wish that Raycast would come there, too. Source: xda-developers.com … [Read More...]

Microsoft sneakily drops DLC discounts that come with Xbox Game Pass

After Microsoft decided to jack up the price of its Xbox Game Pass subscriptions to up to $30 a month, it has another unwelcome surprise for members. In a statement provided to multiple outlets like Insider Gaming, a spokesperson for Microsoft confirmed it has removed the discounts for DLC that come with a Game Pass subscription, replacing them by offering points for its Rewards program.While … [Read More...]

The best Amazon Prime Day deals under $50: Early sales on tech from Apple, Anker, Ring, JBL, Roku and others

Prime Day sales are a great opportunity to nab an expensive bit of shiny new tech you’ve been eying — it’s also an excellent time to get a discount on smaller electronics and accessories. For this list, we compared what’s on sale right now with the stuff we recommend in our guides. For less than $50 each, we found deals on some of our favorite tech including batteries, iPhone paraphernalia, mice, … [Read More...]

4 Linux kernel tweaks I made that actually improved performance

If you want something that offers stability, flexibility, and performance, you'll want to consider a Linux distribution. A major part of what makes this operating system (OS) such an easy recommendation is the kernel, the core of what makes everything work. The Linux kernel manages everything from scheduling processes to managing memory allocation and device communication. It's so good that you … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • Your RAM has more than one XMP profile, and here's when to use the others
  • Ditching smart home subscriptions for open-source Home Assistant
  • I migrated my cloud photos to my self-hosted Immich, here's how
  • I replaced Adobe Premiere with DaVinci Resolve, and I'm not missing out on anything
  • You have to play these Mario games before the Super Mario Galaxy Movie comes out in 2026

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023