{
  "slug": "postmark-mcp",
  "name": "postmark-mcp",
  "aliases": [
    "phanpak"
  ],
  "status": "dormant",
  "firstSeen": "2025-09-17",
  "lastSeen": "2025-09-25",
  "lastReviewed": "2026-09-20T00:00:00Z",
  "summary": "Multiple malicious postmark-mcp versions BCCed mail to the publisher.",
  "description": "This single-branch campaign is retained because the actor published multiple versions of the malicious MCP server.",
  "actor": "phanpak",
  "platforms": [
    "npm"
  ],
  "ttps": [
    {
      "framework": "safe_mcp",
      "id": "data-exfiltration"
    }
  ],
  "timeline": [
    {
      "date": "2025-09-17",
      "branch": "package",
      "id": "postmark-mcp@1.0.16",
      "source": "https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package"
    },
    {
      "date": "2025-09-25",
      "branch": "report",
      "id": "1643-installs",
      "source": "https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/"
    }
  ],
  "iocs": [
    {
      "type": "package",
      "value": "postmark-mcp@1.0.16",
      "firstSeen": "2025-09-17",
      "source": "https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package"
    }
  ],
  "exposedConfigurations": [
    {
      "label": "postmark-mcp is installed as an MCP server",
      "matcher": {
        "some": "mcpServers",
        "where": {
          "field": "package",
          "op": "eq",
          "value": "pkg:npm/postmark-mcp"
        }
      }
    }
  ],
  "advisories": [
    "ACVE-2026-0408"
  ],
  "incidents": [],
  "sources": [
    {
      "url": "https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package",
      "publisher": "Postmark",
      "date": "2025-09-17"
    },
    {
      "url": "https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/",
      "publisher": "Snyk",
      "date": "2025-09-25"
    }
  ],
  "dormantAfterDays": 30
}
