On September 25th 2025, researchers at AI-focussed security firm Koi shared their learnings about what is probably the first malicious MCP in the wild.
“postmark-mcp” was a popular 3rd-party MCP for connecting AI assistants, workflows and agents to Active Campaign’s Postmark service that had been downloaded 1,500 times weekly.
The firm discovered, that a small change made after 15 safe and reliable releases, allowed the MCP to secretly copy all emails sent to an email address the developer had chosen. The breach impacted an estimated 300 organizations, sending between 3,000 and 15,000 emails per day to the attacker.
The MCP allows AI assistants and agents to send all kinds of emails, and because these assistants don’t question the code they’re running, the theft went undetected until Koi’s monitoring system flagged the suspicious change.
The developer deleted the package after being contacted but didn’t respond to inquiries, however already-installed versions continue to forward emails containing passwords, invoices, and confidential information.
Call to action: All coworking operators and workspace software companies using AI tools to handle member communications or operations should audit their systems and remove any installations of postmark-mcp version 1.0.16 or later & begin implementing rules for what MCP assessment and deployments.

