#software-supply-chain-attacks

[ follow ]
Information security
fromTheregister
3 days ago

Fake Postmark MCP npm package stole emails with one-liner

A malicious npm package impersonating Postmark's MCP secretly BCC'd outgoing emails to an attacker, likely exfiltrating thousands of sensitive messages daily.
[ Load more ]