What happened
The malicious postmark-mcp v1.0.16 npm package added a silent BCC header to all email send requests, routing copies to [email protected]. AI agents using this MCP server to send transactional email unknowingly exfiltrated every email to the attacker.