First malicious MCP server hid in one line of code, silently BCC'd user emails
In September 2025, security researchers at Koi Security identified the first known malicious MCP server in the wild, found inside a popular npm package called postmark-mcp. The package had operated legitimately across 15 versions, accumulating around 1,500 weekly downloads, before its maintainer added a hidden Bcc field in version 1.0.16 on September 17, 2025. The change silently forwarded all agent-sent emails — including content, recipients, and attachments — to a domain controlled by the attacker, while the tool continued functioning normally. The package was downloaded 1,643 times before being removed from npm; Postmark confirmed it had no affiliation with the package. Security experts warn the incident exposes a broader risk in AI agent tooling, where a previously vetted dependency can turn hostile in a later update without any visible behavioral change.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in