Friday 26 September 2025 - CSSC
A popular Model Context Protocol (MCP) server used to deploy AI agents has turned malicious in one of its latest updates.
This engine, called Postmark MCP Server, has reached over 1500 weekly downloads on npm, a package manager for the JavaScript programming language, and has been integrated into hundreds of developer workflows.