MCP plus open source plus typosquatting ... what could possibly go wrong? A fake npm package posing as Postmark's MCP (Model Context Protocol) server silently stole potentially thousands of emails a day by adding a single line of code that secretly copied outgoing messages to an attacker-controlled address....
Related Articles
Don't miss out on breaking stories and in-depth articles.