{ads}

First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package



September 29, 2025 at 02:06PM

Cybersecurity researchers have discovered what has been described as the first-ever instance of a Model Context Protocol (MCP) server spotted in the wild, raising software supply chain risks. According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called "postmark-mcp" that copied an official Postmark Labs library of the same name. The

from The Hacker News https://ift.tt/SI3TQmL

0 Response to "First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads