Learn languages naturally with fresh, real content!

Popular Topics
Explore By Region
A fake npm package stole sensitive data by secretly BCCing emails to an attacker's address.
A malicious npm package named "postmark-mcp" impersonated a legitimate Postmark tool, secretly BCCing thousands of emails daily to an attacker-controlled address.
The fake package, downloaded around 1,500 times in a week, exploited the open Model Context Protocol (MCP) ecosystem to steal sensitive data including password resets and financial details.
Security researchers traced the backdoor to a single line of code based on legitimate Postmark GitHub code, routing emails to "phan@giftshop[.]club."
The incident, linked to a compromised MCP server, exposed systemic risks in open-source dependencies and AI tool integration.
GitHub is responding by tightening npm security with shorter token lifetimes and mandatory two-factor authentication for publishing.
Postmark and ActiveCampaign confirmed no involvement and urged users to remove the package, review logs, and rotate credentials.
Un paquete falso de npm robó datos confidenciales enviando secretamente correos electrónicos a la dirección de un atacante.