TGViewer
CatOps CatOps @catops · 5.08K subscribers
Post #2769 2.56K
Is it the first supply chain attack in the MCP world?

A fake Postmark MCP was secretly BCCing all the emails.

Postmark is an SMTP provider. They have already put a statement that it was not developed by them.

The moral of the story is not to blindly trust 3rd party software that doesn’t come from your vendor. Another interesting thing is that the attack itself has nothing to do with LLMs, but the attackers are using the hype around everything AI to embed their malicious code.

#security #ai
The Register One line of malicious npm code led to massive Postmark email heist : MCP plus open source plus typosquatting equals trouble
  • 👍 3
  • 🤯 2
  • 😱 2
  • 👏 1
More from @catops
  1. Oct 1, 2026​​I traded my personal information for this report, so you don’t have to! DataDog presents…
  2. Sep 29, 2026A Cybersecurity books bundle by O’Reilly on Humble Bundle. The bundle is fresh and is stil…
  3. Sep 28, 2026​​For today’s Donations Monday, I’d like to remind you about a fundraiser for a pickup tru…
  4. Sep 26, 2026Here’s Datadog’s take on the increased load on CI. In this article they explain how their…
  5. Sep 25, 2026A new chapter of the CatOps Digest is here! https://newsletter.catops.dev/p/catops-digest-…
  6. Sep 24, 2026Shopify wrote an article on them moving from React Native to the native code for their mob…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →