ThreatPaper
Assessed, Not Confirmed

postmark-mcp was the first malicious MCP server

Assessment

Koi Security, who found it, framed it carefully: believed to be the first publicly documented malicious MCP server. That is a claim about the state of public reporting, and as such it is very likely correct — no earlier published example has been identified. Downstream coverage drops "publicly documented" and reports it as the first malicious MCP server to have existed. That is a different and unknowable claim. MCP servers are configured locally, often from sources that never touch a public registry, and there is no telemetry that would establish an absence. Recorded because "first" is load-bearing here: it is the reason this incident is cited as a turning point, and the qualified version supports that reading perfectly well without asserting something nobody can know.

Where this claim appeared

The Hacker News · 2025-09-29

https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

postmark-mcp: One Line of Code That BCC'd Every Email to an Attacker

Think this assessment is wrong? Report an error.