Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› postmark-mcp Malicious MCP Server 2025: How One Line…
Breach analysis Incident: 25 Sep 2025

postmark-mcp Malicious MCP Server 2025: How One Line of Code Made AI Agents Copy Every Email to an Attacker

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: AI agents NHI
Attack route: Supply chain Identities: AI agent API key
On this page

In September 2025 Koi Security found that an npm package called postmark-mcp, which posed as an MCP server for the Postmark email service, had been quietly copying every email it sent to an attacker. The package let AI assistants send email through a user's Postmark account. Its first fifteen versions worked as advertised. Version 1.0.16, released on 17 September 2025, added a single line that blind-copied each outgoing message to an address at the giftshop[.]club domain. Postmark, which had no connection to the package, published a warning on 25 September. The Hacker News counted 1,643 downloads, and Koi's chief technology officer estimated that hundreds of organisations may have been sending email through it. Postmark said it knew of only one of its customers that used the package. Koi called it "the world's first sighting of a real-world malicious MCP server". The developer deleted the package from npm, but installed copies kept running until removed.

Key takeaways

  • postmark-mcp copied the code of Postmark's real MCP server, which is published on GitHub, not npm, and released it on npm under a trusted-sounding name from an account called "phanpak".
  • Version 1.0.16, released 17 September 2025, added a hidden BCC to the server's send-email tool, so every message an AI agent sent was also delivered to the attacker, through the victim's own Postmark account.
  • The package had 1,643 downloads according to The Hacker News. Koi Security's estimates of affected organisations are its own; Postmark knew of only one customer that used it.
  • Postmark said it "had absolutely nothing to do with this package or the malicious activity" and that its own API and services were not affected.
  • The identity lesson: an MCP server acts with the agent's delegated credentials, so installing one is granting a stranger the same access as your agent.

At a glance

OrganisationsUsers of the unofficial postmark-mcp npm package, including at least one Postmark customer; Postmark (ActiveCampaign) was impersonated, not breached
WhenPackage first published 15 September 2025; malicious version 1.0.16 released 17 September 2025; public warnings 25 September 2025
AttackerThe developer behind the npm account "phanpak", which maintains 31 other packages; not linked to a known group
Entry pointA look-alike MCP server package on npm that users installed into their AI assistants
Identities abusedThe AI agent's email-sending tool and the user's Postmark server token, which sent the hidden BCC copies
ImpactEmails sent by AI agents through the package, including their attachments and any secrets or personal data in them, copied to an attacker-controlled address
CategoryAgentic AI and AI agents, NHI. Incident class: confirmed AI-agent breach (malicious MCP tool exfiltrated email sent by AI agents)

What happened

The Model Context Protocol lets AI assistants such as Claude or Cursor call tools provided by small servers that users install locally. Postmark, a transactional email service owned by ActiveCampaign, publishes an official MCP server on GitHub so agents can send email through a customer's Postmark account. Postmark says it had never published an MCP server on npm. On 15 September 2025, according to The Hacker News and Snyk, a package called postmark-mcp appeared on npm, built from a copy of Postmark's code. It was published from an npm account, "phanpak", that maintained 31 other packages.

For fifteen versions the package did exactly what it claimed. Then version 1.0.16, released on 17 September, added one line to the send-email tool. Every outgoing message gained a blind copy to an address at giftshop[.]club. Snyk's comparison of versions 1.0.15 and 1.0.18 found that line was the only notable change. Because the server sent mail through the user's own Postmark credentials, the copies went out from the victim's account, and nothing in the agent's response showed them. Snyk notes that the exposed data includes message content, attachments and headers, which may contain secrets, tokens and personal or regulated data.

Koi Security's chief technology officer Idan Dardikman found the backdoor. He called it "the world's first sighting of a real-world malicious MCP server", according to The Hacker News, and told CSO Online: "One developer. One line of code. Thousands upon thousands of stolen emails." He also warned that "These MCP servers run with the same privileges as the AI assistants themselves". His estimates of scale, as reported by The Register, were that about 20 percent of roughly 1,500 weekly downloads were in use, around 300 organisations each sending 10 to 50 emails a day. CSO Online reported his figures differently, so they are best treated as Koi's rough estimate rather than a measurement.

Postmark published a notice on 25 September saying it "had absolutely nothing to do with this package or the malicious activity" and that its legitimate API and services were unaffected. It told users to remove the package, check their email logs and consider rotating any credentials sent by email during the compromise period. The Register reported that Postmark knew of only one customer that had actually used the package. By then the developer had deleted it from npm, which, as CSO Online notes, does not remove copies already installed.

Timeline

DateEvent
15 September 2025postmark-mcp version 1.0.0 is published to npm by the account "phanpak".
17 September 2025Version 1.0.16 adds the hidden BCC; later versions up to 1.0.18 keep it.
25 September 2025Postmark and Snyk publish warnings; the package no longer appears on npm.
26 September 2025CSO Online reports Koi Security's findings and estimates.
29 September 2025The Hacker News and The Register report the incident.

How it happened: the identity attack path

  1. Impersonate a trusted tool. The attacker copied Postmark's open-source MCP server and published it on npm, where Postmark had no official package.
  2. Build trust first. Fifteen clean versions let the package collect users and look legitimate.
  3. Inherit the agent's access. Users configured the server with their Postmark credentials and let their AI assistants send email through it.
  4. Add one line. Version 1.0.16 blind-copied every outgoing message to the attacker, sent through the victim's own Postmark account.
  5. Vanish, leaving the backdoor running. When the package was exposed, the developer deleted it, but installed copies kept forwarding email until users removed them.

Impact

  • Confirmed: a malicious MCP server on npm copied every email it sent to an attacker-controlled address; Postmark knew of at least one customer that used it.
  • Reach: 1,643 downloads according to npm-stat figures cited by The Hacker News.
  • Estimated, by Koi Security: around 300 organisations and 3,000 to 15,000 emails a day, as reported by The Register. These are the researcher's estimates, not confirmed counts.
  • Potential: password resets, invoices, internal messages and any keys or tokens in email bodies or attachments exposed to the attacker; reuse of those secrets elsewhere.

What this means for NHI and AI agent security

An MCP server is a non-human identity in its own right: code that acts with the agent's delegated credentials and does whatever the agent asks of it, plus whatever its author adds. Users vet the agent, but they rarely vet each tool. postmark-mcp needed no exploit and no stolen password. It was installed willingly, given a real Postmark token and called by agents doing their normal jobs. The theft ran through legitimate credentials, in legitimate traffic, which makes it very hard to spot from logs alone.

This is the npm supply chain problem, familiar from the Shai-Hulud worm the same month, moved into the agent's toolbox. The ClawHub malicious skills campaign later used the same trust in agent extensions. Defences are identity controls: install MCP servers only from their publisher's official source, give each server its own narrowly scoped credential and watch what the tool actually does with it. See our MCP Security Guide and AI Supply Chain and AI-BOM Guide.

Recommendations

  • Remove postmark-mcp and rotate what it touched. Uninstall the package, block the giftshop[.]club domain, rotate Postmark API and SMTP credentials and any secrets sent by email while it was installed. See our Leaked Credential Response Playbook.
  • Install MCP servers only from the publisher. Check that the package comes from the service's official repository or registry account before adding it to an agent. See our MCP Security Guide.
  • Pin and review MCP server versions. Lock tools to reviewed versions and inspect changes before upgrading, as a single added line was enough here. See our AI Supply Chain and AI-BOM Guide.
  • Give each MCP server its own scoped credential. Use a dedicated, limited token per tool so a malicious server cannot reach more than its job. See our AI Agent Authorisation Guide.
  • Check email logs for hidden recipients. Review provider logs for unexpected BCC addresses on messages sent by agents and integrations.
  • Keep an inventory of agent tools. Know which MCP servers are installed across your developers' and users' machines. See our Shadow AI Discovery Guide.

Frequently asked questions

What was the postmark-mcp malicious MCP server?

postmark-mcp was an unofficial npm package that imitated Postmark's MCP server for AI assistants. From version 1.0.16, released on 17 September 2025, it secretly blind-copied every email it sent to an attacker-controlled address. Postmark had no involvement with it.

Was Postmark hacked?

No. Postmark says it had nothing to do with the package and that its API and services were not affected. The package used victims' own Postmark credentials to send the hidden copies, so the theft happened on users' machines, not in Postmark's systems.

What should I do if I installed postmark-mcp?

Remove the package, rotate your Postmark API and SMTP credentials and any secrets that were sent by email while it was installed, check email logs for BCC traffic to giftshop[.]club, and switch to Postmark's official MCP server from its GitHub repository.

Smithery.ai MCP hosting breach 2025 · Shai-Hulud npm worm first wave · ClawHub malicious skills 2026 · MCP Security Guide · AI Supply Chain and AI-BOM Guide

How NHI Mgmt Group can help

Every MCP server an agent uses is another identity holding real credentials. We help teams inventory agent tools, scope the credentials they receive and set rules for which servers can be installed. See our NHI Foundation Level Training Course.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org