Unofficial Postmark MCP npm silently stole users’ emails

Unofficial Postmark MCP npm silently stole users’ emails











A npm package copying the official ‘postmark-mcp’ project on GitHub turned bad with the latest update that added a single line of code to exfiltrate all its users’ email communication. […]






Bill Toulas





Go to bleepingcomputer





Posted

in

, ,

by