Information Regarding Malicious "postmark-mcp" Package
A malicious npm package called "postmark-mcp" was discovered impersonating Postmark and stealing user emails. This fraudulent package, which we had no involvement with, built trust through 15 versions before adding a backdoor in version 1.0.16 that secretly BCC'd emails to an external server. If you've used this fake package, remove it immediately and check your email logs for suspicious activity. The legitimate Postmark API and services remain secure and unaffected. Always verify packages through our official documentation—if it's not listed there, don't use it.
Continue reading • Postmark team wrote in Engineering