• Alerts
  • Events
  • DCR
    • Explore Cyware Products
    Alerts Events DCR
    Go to listing page

    Fake Postmark MCP npm package stole emails with one-liner

    • Malware and Vulnerabilities
    • September 30, 2025
    • The Register
    A fake npm package posing as Postmark's MCP (Model Context Protocol) server silently stole potentially thousands of emails a day by adding a single line of code that secretly copied outgoing messages to an attacker-controlled address.
    Read More
    • Npm
    • Model Context Protocol (MCP)
    Cyware Publisher

    Publisher

    Previous

    Akira ransomware: From SonicWall VPN login to encryptio ...

    Malware and Vulnerabilities

    Next

    ‘Widespread’ breach let hackers steal employee data fro ...

    Breaches and Incidents


    RESOURCES
    Cyber Fusion Center Guide
    EVENTS

    News and Updates, Hacker News

    Get in touch with us now!

    1-855-692-9927


    Download Cyware Social App

    Terms of Use Privacy Policy © 2023