First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package

Cybersecurity researchers have discovered what has been described as the first-ever instance of a malicious Model Context Protocol (MCP) server spotted in the wild, raising software supply chain risks.
According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called “postmark-mcp” that copied an official Postmark Labs library of the same name.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks

Next Post

Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security

Related Posts
Total
0
Share