ThreatPaper
Unverified

Around 300 organisations were affected by the postmark-mcp backdoor

Assessment

The figure is an assumption applied to a download count, and both halves are unstable. The assumption is explicit and the researchers presented it as one: roughly 20% of people who downloaded the package were estimated to be actively using it. That is a reasonable working estimate and it is not a measurement. The download count it is applied to is reported three different ways across coverage of the same research: 1,500 weekly downloads, 1,643 total downloads, and 15,000 users. Those cannot all describe the same quantity, and 300 is 20% of the first of them — which means the most-quoted impact figure in this incident depends on which of three inconsistent numbers a given article happened to use. What nobody has published is the number that matters: how many organisations actually sent mail through a version from 1.0.16 onward during the eight days it was available. A download is not an installation, an installation is not a configured MCP server, and a configured server is not one that was asked to send anything. Rated Unverified rather than False because the estimate may well be close. The point is that it is an assumption resting on a disputed input, and it circulates as a count.

Where this claim appeared

Infosecurity Magazine · 2025-09-30

https://www.infosecurity-magazine.com/news/malicious-ai-agent-server/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

postmark-mcp: One Line of Code That BCC'd Every Email to an Attacker

Think this assessment is wrong? Report an error.