# PIR-2026-0036 - Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email

- `id`: PIR-2026-0036
- `title`: Trojan MCP server impersonating Postmark silently BCC's every agent-sent email to the attacker - first documented in-wild malicious MCP server
- `date_occurred`: 2025-09-17 08:59 UTC (v1.0.16 with the BCC backdoor published; exposure window through 2025-09-25)
- `date_detected`: ~2025-09-24/25 (Koi Security)
- `date_disclosed`: 2025-09-25/26 (Koi writeup; press 2025-09-26; Postmark advisory; npm unpublish 2025-09-25 03:31 UTC)
- `status`: corroborated (public npm artifact + registry metadata + multi-vendor analysis)

### The agent
- `agent_description`: Not one agent - a poisoned tool wired into many operators' stacks. "postmark-mcp" on npm impersonated Postmark's official MCP server (code copied from the legitimate open-source repo), giving AI assistants (Claude, Cursor, etc.) email-sending via the operator's Postmark credentials.
- `operator_type`: many downstream (individuals + orgs); attacker: individual npm author ("phanpak", exfil address phan@giftshop.club)
- `autonomy_level`: varies downstream; the tool executed inside trusted agent pipelines with no review of tool behavior
- `model_stack`: n/a (tool-level compromise, model-agnostic)
- `harness`: MCP servers in agent workflows

### Authority
- `authority_scope`: external comms (send email as the operator); data access (content of all outgoing email - password resets, invoices, internal memos)
- `funds_at_risk_usd`: unknown (indirect: credentials and reset links transited the exfiltrated mail)
- `blast_radius`: customers/third parties (Koi estimate ~300 orgs; plus every counterparty of mail sent through the tool)

### The failure
- `failure_locus`: tool-mcp
- `root_cause`: supply-chain-compromise - primary (v0.1); contributing: adversarial-other (deliberate malicious publisher). No injection, no model failure - the tool itself was hostile.
- `mechanism`: Author published postmark-mcp on 2025-09-15 as a working copy of Postmark's official MCP server and pushed 13 registry versions in two days. v1.0.16 (2025-09-17) added one line BCC'ing every outgoing email to phan@giftshop.club. Because MCP tools run inside trusted pipelines with their behavior unreviewed, agents kept sending mail normally while every message was copied out, until npm unpublished the package on 2025-09-25.
- `adversary_present`: yes
- `exploitation_status`: in-wild-exploited

### Impact
- `severity`: loss (confidentiality - real installs, real mail flow; but see confidence: exfil volume inferred, not measured)
- `direct_loss_usd`: unknown; no monetary theft publicly attributed
- `indirect_loss_usd`: unknown (credential rotation + email-log audits across affected orgs)
- `downtime`: none
- `data_exposure`: outgoing email of v1.0.16+ installers over ~8 days (~1,500 weekly downloads per Koi; actual volume never measured)

### Detection and recovery
- `detected_by`: third-party (Koi Security)
- `time_to_detect`: ~7-8 days from backdoored release to discovery
- `time_to_recover`: npm removal 2025-09-25; per-org: uninstall, rotate Postmark credentials, audit for BCC traffic
- `remediation`: package unpublished; Postmark advisory disavowing it; vendor removal/rotation guidance
- `controls_that_worked`: none pre-detection - no registry or harness control inspects MCP tool behavior; the BCC line sat in public source the entire window (reviewability existed, review did not). Post-detection, unpublish + advisories bounded further spread.
- `structural_fix`: none ecosystem-wide at the time; became the canonical case for MCP supply-chain vetting

### Evidence
- `telemetry_grade`: split - mechanism effectively witnessed (public npm artifact; registry publish/unpublish timestamps independently verified for this record); impact telemetry none (the attacker's inbox is the only complete record of what was taken)
- `sources`:
  - https://registry.npmjs.org/postmark-mcp (primary metadata; re-fetched 2026-08-15, publish/unpublish timestamps intact and matching this record)
  - https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
  - https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package (impersonated vendor)
  - https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/
  - https://www.darkreading.com/application-security/malicious-mcp-server-exfiltrates-secrets-bcc
  - All five URLs verified resolving 2026-08-15.
  - `independence`: good - Koi's discovery corroborated by two independent security vendors, the impersonated vendor, and the registry itself.
- `confidence`: high on mechanism and timeline (registry-verified); low on impact magnitude (org and email counts are extrapolations from download stats)

### Verification notes
1. Registry-verified: created 2025-09-15T10:44Z; v1.0.16 at 2025-09-17T08:59Z; all 16 versions unpublished 2025-09-25T03:31Z. Candidate dates confirmed exactly.
2. Classification corrected for v0.1: intake had `adversarial-other (malicious MCP tool)` under the v0 taxonomy; primary is now `supply-chain-compromise`, locus `tool-mcp`.
3. The widely reported "trust built over 15 clean releases" is version-number theater: npm shows 13 published versions before 1.0.16, all within two days - a compressed sprint, not long grooming.
4. "~300 orgs, thousands of emails/day" are Koi estimates from ~1,500 weekly downloads, not measured exfiltration; recorded as estimates only.
