id: PIR-2026-0036title: Trojan MCP server impersonating Postmark silently BCC's every agent-sent email to the attacker - first documented in-wild malicious MCP serverdate_occurred: 2025-09-17 08:59 UTC (v1.0.16 with the BCC backdoor published; exposure window through 2025-09-25)date_detected: ~2025-09-24/25 (Koi Security)date_disclosed: 2025-09-25/26 (Koi writeup; press 2025-09-26; Postmark advisory; npm unpublish 2025-09-25 03:31 UTC)status: corroborated (public npm artifact + registry metadata + multi-vendor analysis)agent_description: Not one agent - a poisoned tool wired into many operators' stacks. "postmark-mcp" on npm impersonated Postmark's official MCP server (code copied from the legitimate open-source repo), giving AI assistants (Claude, Cursor, etc.) email-sending via the operator's Postmark credentials.operator_type: many downstream (individuals + orgs); attacker: individual npm author ("phanpak", exfil address phan@giftshop.club)autonomy_level: varies downstream; the tool executed inside trusted agent pipelines with no review of tool behaviormodel_stack: n/a (tool-level compromise, model-agnostic)harness: MCP servers in agent workflowsauthority_scope: external comms (send email as the operator); data access (content of all outgoing email - password resets, invoices, internal memos)funds_at_risk_usd: unknown (indirect: credentials and reset links transited the exfiltrated mail)blast_radius: customers/third parties (Koi estimate ~300 orgs; plus every counterparty of mail sent through the tool)failure_locus: tool-mcproot_cause: supply-chain-compromise - primary (v0.1); contributing: adversarial-other (deliberate malicious publisher). No injection, no model failure - the tool itself was hostile.mechanism: Author published postmark-mcp on 2025-09-15 as a working copy of Postmark's official MCP server and pushed 13 registry versions in two days. v1.0.16 (2025-09-17) added one line BCC'ing every outgoing email to phan@giftshop.club. Because MCP tools run inside trusted pipelines with their behavior unreviewed, agents kept sending mail normally while every message was copied out, until npm unpublished the package on 2025-09-25.adversary_present: yesexploitation_status: in-wild-exploitedseverity: loss (confidentiality - real installs, real mail flow; but see confidence: exfil volume inferred, not measured)direct_loss_usd: unknown; no monetary theft publicly attributedindirect_loss_usd: unknown (credential rotation + email-log audits across affected orgs)downtime: nonedata_exposure: outgoing email of v1.0.16+ installers over ~8 days (~1,500 weekly downloads per Koi; actual volume never measured)detected_by: third-party (Koi Security)time_to_detect: ~7-8 days from backdoored release to discoverytime_to_recover: npm removal 2025-09-25; per-org: uninstall, rotate Postmark credentials, audit for BCC trafficremediation: package unpublished; Postmark advisory disavowing it; vendor removal/rotation guidancecontrols_that_worked: none pre-detection - no registry or harness control inspects MCP tool behavior; the BCC line sat in public source the entire window (reviewability existed, review did not). Post-detection, unpublish + advisories bounded further spread.structural_fix: none ecosystem-wide at the time; became the canonical case for MCP supply-chain vettingtelemetry_grade: split - mechanism effectively witnessed (public npm artifact; registry publish/unpublish timestamps independently verified for this record); impact telemetry none (the attacker's inbox is the only complete record of what was taken)sources:independence: good - Koi's discovery corroborated by two independent security vendors, the impersonated vendor, and the registry itself.confidence: high on mechanism and timeline (registry-verified); low on impact magnitude (org and email counts are extrapolations from download stats)adversarial-other (malicious MCP tool) under the v0 taxonomy; primary is now supply-chain-compromise, locus tool-mcp.