PipeRoll - Agent Incident Registry · about · contribute · data · notes · constitution · seismograph ↗

Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email

PipeRoll seal - registered recordPIR-2026-0036
Occurred
2025-09-17 08:59 UTC
Disclosed
2025-09-25/26
Operator
many downstream
Blast radius
customers/third parties
Root cause
supply-chain-compromise
Failure locus
tool-mcp
Severity
loss
Exploitation
in-wild-exploited
Direct loss (USD)
unknown; no monetary theft publicly attributed
Telemetry
split - mechanism effectively witnessed
Confidence
high on mechanism and timeline
Status
corroborated
Cite as: PipeRoll PIR-2026-0036, Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email (2025-09) - https://piperoll.org/pir/2026-0036 markdown. Registered 2026-08-15 by Srinivas G.

PIR-2026-0036 - Malicious "postmark-mcp" npm package BCC-exfiltrates agent-sent email

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Verification notes

  1. Registry-verified: created 2025-09-15T10:44Z; v1.0.16 at 2025-09-17T08:59Z; all 16 versions unpublished 2025-09-25T03:31Z. Candidate dates confirmed exactly.
  2. Classification corrected for v0.1: intake had adversarial-other (malicious MCP tool) under the v0 taxonomy; primary is now supply-chain-compromise, locus tool-mcp.
  3. The widely reported "trust built over 15 clean releases" is version-number theater: npm shows 13 published versions before 1.0.16, all within two days - a compressed sprint, not long grooming.
  4. "~300 orgs, thousands of emails/day" are Koi estimates from ~1,500 weekly downloads, not measured exfiltration; recorded as estimates only.

More supply-chain-compromise records

← older: PIR-2026-0035 · registry · newer: PIR-2026-0037 →