Today's Core Dump is brought to you by ThreatPerspective

The Register - Security

One line of malicious npm code led to massive Postmark email heist

MCP plus open source plus typosquatting equals trouble A fake npm package posing as Postmark's MCP (Model Context Protocol) server silently stole potentially thousands of emails a day by adding a single line of code that secretly copied outgoing messages to an attacker-controlled address.

Published: 2025-09-29T20:44:35











© Segmentation Fault . All rights reserved.

Privacy | Terms of Use | Contact Us