Is it the first supply chain attack in the MCP world?
A fake Postmark MCP was secretly BCCing all the emails.
Postmark is an SMTP provider. They have already put a statement that it was not developed by them.
The moral of the story is not to blindly trust 3rd party software that doesn’t come from your vendor. Another interesting thing is that the attack itself has nothing to do with LLMs, but the attackers are using the hype around everything AI to embed their malicious code.
#security #ai
Post #2769
2.56K