First Malicious MCP Server Discovered in Fake Postmark-MC NPM Package
Koi Security reports the first malicious MCP server hidden in a fake Postmark-MC NPM package, highlighting new risks in software supply chain attacks.
First Malicious MCP Server Discovered in Fake Postmark-MC
The team at Koi Security has reported a discovery that could mark a turning point in cybersecurity: the detection of the first malicious Model Context Protocol (MCP) server in the public domain.
The threat was hidden in an NPM package called postmark-mcp, disguised under the name of the legitimate Postmark Labs library.
What Happened?
According to Idan Dardikman, CTO of Koi Security, starting with version 1.0.16 the package began to forward all copies of emails to the attacker’s personal server.
This is the first-ever global detection of a malicious MCP server in action. For Koi Security, it highlights a growing concern:
“The attack surface of supply chain endpoints is gradually becoming the largest threat area for enterprises.”
Scope of the Attack
The package was uploaded by a developer under the alias “fanfanpak” on September 15, 2025. In just a few days, it had already surpassed 1.600 installations.
Following the publication of Koi Security’s report, the library was removed from NPM. Still, the incident demonstrates how attackers are increasingly exploiting the software supply chain as an entry point.
Malicious use of MCP introduces several risks:
• Theft of sensitive data.
• Leakage of confidential information.
• Injection of additional malicious code into corporate processes.
Recommendations for Developers and Enterprises
Cybersecurity experts stress that MCP-based attacks are only beginning to emerge. They recommend:
• Always verifying the official source of packages.
• Carefully reviewing dependency updates.
• Implementing supply chain monitoring systems.
The takeaway is clear: as an emerging technology, MCP has already become an attractive target for attackers and requires heightened oversight.
Discover all attacks and leaks and check if your data has been compromised at:
Darkeye Research Team
SamuelTracking ransomware crews, breach disclosures and the tooling that matters — field notes from the Darkeye desk.
Intel briefing
Get breach reports before they trend
Ransomware intel and breach disclosures in your inbox. Signal only, no noise.
Read next //
Hacking F5: Attack at the Heart of Global Cybersecurity
F5 Networks suffers a state-sponsored cyberattack. Source code and vulnerabilities stolen, risking supply chain, federal agencies, and critical infrastructure.
Keep investigating //
Discussion (0)
Sign in to join the discussion
Share your take with the Darkeye community.
No comments yet. Be the first to weigh in.