Just in:
Security Is the New Market Access: Kigen Is Leading the IoT Security Mandate // Foreign bank branch fined over compliance failures // Putting Scientific Research Agents Within Reach — SCNet.AI Accelerates AI4S Innovation Powered by AI & HPC // Collapse Of TMC In Bengal Has Given A Big Opportunity For A Left Turn-Around // Varenne Capital opens Dubai base for regional push // Biosphere Labs strengthens Abu Dhabi biotech hub // Gaslight malware exposes AI triage blind spot // Dubai summit sets global sports agenda // OneGrowth 2026: Shared AI Token Era Ahead China Telecom Global Partner Conference Held // HKRITA Signs MoU with Jeanologia and Looptworks to Establish the Green Machine Circular Textile Ecosystem, Marking a Breakthrough in Scalable Textile Recycling // Pulsar International (“Pulsar”) announces agreement as an authorized reseller of Amazon Leo to bring high-speed satellite internet to commercial maritime customers // GEMS enrolment softens as war delays relocations // Global Residency by Investment: How Investors Are Choosing in 2026 // OTC & Partners Opens 2026 with Strong Cross-Border Mandates and Strategic Expansion // Paddles up! Hong Kong marks 50 Years of international dragon boat thrills // Valve’s pricier Steam Machine tests PC ambitions // Hong Kong celebrates surge of global enterprises driving investment and opportunities // Baghdad raises stakes in OPEC quota clash // EVB Successfully Concludes Power2Drive Europe 2026 With Advanced EV Charging Solutions // DIFC growth lifts Dubai finance rank //

MCP Package Hijack Funnels Sensitive Emails to Attacker

A malicious version of the npm package postmark-mcp, masquerading as a tool to enable AI agents to send email via Postmark, has been uncovered siphoning off every message it processes. The compromised version, beginning with release 1.0.16, silently adds a “blind carbon copy” to phan@giftshop. club, forwarding confidential correspondence to the attacker. The discovery marks the first confirmed case of a real-world, in-the-wild compromise of an MCP server.

Security researchers at Koi Security traced the attack by flagging anomalous code behavior in the version upgrade. They found that the malicious package was a clone of a legitimate project maintained by ActiveCampaign, with just one additional line of code enabling the BCC backdoor. The developer then removed the package from npm after detection, but that action does not stop already deployed instances from continuing to leak data.

MCP infrastructure enables AI assistants and agents to act on tasks such as emailing, database queries, and internal automation. Because these tools are often granted “god-mode” access—full read/write permissions—they are high-risk components if compromised. Researchers warn that MCP servers are inadequately audited in many security architectures, bypassing traditional checks like vendor assessments, data loss prevention systems, and email gateway monitoring.

Analysis by the academic community supports the idea that MCP frameworks remain a weak link in AI security. A recent study illustrates how even minimal or simple MCP deployments can serve as trojan tools, facilitating cross-server data exfiltration with little sophistication required. Attackers need not be advanced; undergraduate-level skills can be sufficient to weaponise trust relationships between agent software and tool providers.

ADVERTISEMENT

Koi’s risk engine estimates that the blast radius of the attack could reach thousands of emails per organisation daily. In many cases, the exfiltrated content could include password resets, invoices, financial data, internal memos, or API tokens. Even if the malicious package is removed from central repositories, compromised host systems remain vulnerable until the binary or dependency is purged.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com
Just in:
Biosphere Labs strengthens Abu Dhabi biotech hub // Avalanche forms payments alliance with VanEck // OTC & Partners Opens 2026 with Strong Cross-Border Mandates and Strategic Expansion // VinEnergo partners with SunAsia Energy to develop Solar-on-Water projects integrated with aquaculture in the Philippines // Gaslight malware exposes AI triage blind spot // Pulsar International (“Pulsar”) announces agreement as an authorized reseller of Amazon Leo to bring high-speed satellite internet to commercial maritime customers // Security Is the New Market Access: Kigen Is Leading the IoT Security Mandate // Foreign bank branch fined over compliance failures // Baghdad raises stakes in OPEC quota clash // OneGrowth 2026: Shared AI Token Era Ahead China Telecom Global Partner Conference Held // Dubai summit sets global sports agenda // Global Residency by Investment: How Investors Are Choosing in 2026 // AI browsers face new credential leak warning // Rubio seeks Gulf backing for Iran accord // HKRITA Signs MoU with Jeanologia and Looptworks to Establish the Green Machine Circular Textile Ecosystem, Marking a Breakthrough in Scalable Textile Recycling // GEMS enrolment softens as war delays relocations // Hong Kong celebrates surge of global enterprises driving investment and opportunities // From Millennium Xuan Paper to Contemporary Visual Storytelling: China’s Intangible Cultural Heritage Sets Off Again // Christopher Aleo Strengthens His Gulf Presence with a New Tourism Investment in Oman // DIFC growth lifts Dubai finance rank //