Learn languages naturally with fresh, real content!

tap to translate recording

Explore By Region

flag A fake npm package stole sensitive data by secretly BCCing emails to an attacker's address.

flag A malicious npm package named "postmark-mcp" impersonated a legitimate Postmark tool, secretly BCCing thousands of emails daily to an attacker-controlled address. flag The fake package, downloaded around 1,500 times in a week, exploited the open Model Context Protocol (MCP) ecosystem to steal sensitive data including password resets and financial details. flag Security researchers traced the backdoor to a single line of code based on legitimate Postmark GitHub code, routing emails to "phan@giftshop[.]club." flag The incident, linked to a compromised MCP server, exposed systemic risks in open-source dependencies and AI tool integration. flag GitHub is responding by tightening npm security with shorter token lifetimes and mandatory two-factor authentication for publishing. flag Postmark and ActiveCampaign confirmed no involvement and urged users to remove the package, review logs, and rotate credentials.

3 Articles