PSA: First malicious MCP detected & dissected

On September 25th 2025, researchers at AI-focussed security firm Koi shared their learnings about what is probably the first malicious MCP in the wild.

postmark-mcp” was a popular 3rd-party MCP for connecting AI assistants, workflows and agents to Active Campaign’s Postmark service that had been downloaded 1,500 times weekly.

The firm discovered, that a small change made after 15 safe and reliable releases, allowed the MCP to secretly copy all emails sent to an email address the developer had chosen. The breach impacted an estimated 300 organizations, sending between 3,000 and 15,000 emails per day to the attacker.

The MCP allows AI assistants and agents to send all kinds of emails, and because these assistants don’t question the code they’re running, the theft went undetected until Koi’s monitoring system flagged the suspicious change.

The developer deleted the package after being contacted but didn’t respond to inquiries, however already-installed versions continue to forward emails containing passwords, invoices, and confidential information.

Call to action: All coworking operators and workspace software companies using AI tools to handle member communications or operations should audit their systems and remove any installations of postmark-mcp version 1.0.16 or later & begin implementing rules for what MCP assessment and deployments.

Insights, geekiness, and updates in your inbox?

Subscribe to get free Syncaroo updates via email today.

Share This Post

Industry Trends

Why the Best Integration Projects Never Really End

Learn what Forward Deployed Engineers (FDEs) are, why companies like Palantir, AWS, Anthropic and OpenAI are embracing the model, and why it is particularly well suited to commercial real estate and flex space technology.

Shall we?

We look forward to chatting with you.