# Malicious MCP Server on npm postmark-mcp Harvests Emails

DevFeed: [Malicious MCP Server on npm postmark-mcp Harvests Emails](<https://devfeed.tech/articles/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails-8009.md>)

Original publisher: [Read original article](<https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/>)

Author: Liran Tal

Published: 2025-09-25T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [npm](<https://devfeed.tech/topics/npm.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [toolchains](<https://devfeed.tech/topics/toolchains.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [incident](<https://devfeed.tech/tags/incident.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

## AI overview

This security article reports that the npm package postmark-mcp, an MCP Server for sending email through Postmark, was modified in September 2025 to secretly add a BCC forwarding emails to an external domain. It outlines the incident timeline, the email data and credentials potentially at risk, and mitigation steps including uninstalling the package, rotating credentials, reviewing email logs, and scanning with Snyk's MCP-Scan.

## Source excerpt

Urgent security alert: On September 25, 2025, the npm package 'postmark-mcp' was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, including uninstalling, rotating credentials, and scanning with Snyk's MCP-Scan.