GitHub announced a broader plan to harden the npm supply chain as a malicious package on the registry highlighted how attackers can abuse trust in emerging AI tooling. The package, postmark-mcp, impersonated or reposted a legitimate Model Context Protocol (MCP) server for the Postmark email service and later introduced a subtle payload rather than overt malware, underscoring the risk of seemingly benign packages in public repositories.
According to reporting on the incident, the malicious MCP package silently added a BCC recipient to emails sent through an AI agent, potentially leaking password resets, security alerts, receipts, and other sensitive messages to an attacker-controlled address. The case was described as a software supply-chain attack adapted to the MCP ecosystem, and recommendations focused on using official MCP servers from trusted sources, enforcing least privilege and authentication, reviewing code, and strengthening package verification as npm security controls evolve.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
A malicious npm package named postmark-mcp was identified as impersonating or reposting a legitimate MCP server for the Postmark email service. The package later introduced a subtle payload that added a BCC recipient to emails sent through an AI agent, potentially exposing sensitive messages to an attacker-controlled address.
GitHub published a plan for a more secure npm supply chain, outlining security changes for the npm ecosystem. The announcement marks a formal response to supply-chain risk in the package registry.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.