PipeRoll - Agent Incident Registry

PIR-2026-0036

Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email
Cite as: PipeRoll PIR-2026-0036, Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email (2025-09) - https://piperoll.org/pir/2026-0036

PIR-2026-0036 - Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Verification notes

  1. Registry-verified: created 2025-09-15T10:44Z; v1.0.16 at 2025-09-17T08:59Z; all 16 versions unpublished 2025-09-25T03:31Z. Candidate dates confirmed exactly.
  2. Classification corrected for v0.1: intake had adversarial-other (malicious MCP tool) under the v0 taxonomy; primary is now supply-chain-compromise, locus tool-mcp.
  3. The widely reported "trust built over 15 clean releases" is version-number theater: npm shows 13 published versions before 1.0.16, all within two days - a compressed sprint, not long grooming.
  4. "~300 orgs, thousands of emails/day" are Koi estimates from ~1,500 weekly downloads, not measured exfiltration; recorded as estimates only.