MCP Package Hijack Funnels Sensitive Emails to Attacker

A malicious version of the npm package postmark-mcp, masquerading as a tool to enable AI agents to send email via Postmark, has been uncovered siphoning off every message it processes. The compromised version, beginning with release 1.0.16, silently adds a “blind carbon copy” to phan@giftshop. club, forwarding confidential correspondence to the attacker. The discovery marks the first confirmed case of a real-world, in-the-wild compromise of an MCP server.

Security researchers at Koi Security traced the attack by flagging anomalous code behavior in the version upgrade. They found that the malicious package was a clone of a legitimate project maintained by ActiveCampaign, with just one additional line of code enabling the BCC backdoor. The developer then removed the package from npm after detection, but that action does not stop already deployed instances from continuing to leak data.

MCP infrastructure enables AI assistants and agents to act on tasks such as emailing, database queries, and internal automation. Because these tools are often granted “god-mode” access—full read/write permissions—they are high-risk components if compromised. Researchers warn that MCP servers are inadequately audited in many security architectures, bypassing traditional checks like vendor assessments, data loss prevention systems, and email gateway monitoring.

Analysis by the academic community supports the idea that MCP frameworks remain a weak link in AI security. A recent study illustrates how even minimal or simple MCP deployments can serve as trojan tools, facilitating cross-server data exfiltration with little sophistication required. Attackers need not be advanced; undergraduate-level skills can be sufficient to weaponise trust relationships between agent software and tool providers.

Koi’s risk engine estimates that the blast radius of the attack could reach thousands of emails per organisation daily. In many cases, the exfiltrated content could include password resets, invoices, financial data, internal memos, or API tokens. Even if the malicious package is removed from central repositories, compromised host systems remain vulnerable until the binary or dependency is purged.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
LatAm gushers and possible Venezuela exit a nightmare for Opec // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Putin holds talks with Pezeshkian in Bishkek // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Rodríguez faces broad backlash over US oil pact // What Shein’s $27bn IPO means for Mubadala // US-Iran strikes revive confrontation across Hormuz and Jordan // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Jordan downs eight missiles as Iran targets US bases // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Schnabel urges programmable central bank money on-chain // Apple raises evidence-destruction claims against OpenAI // Qatar economy contracts 7% as energy output slumps // Student coder nets $20,000 from Telegram Algorithm Cup //