postmark-mcp was the first malicious MCP server
Assessment
Koi Security, who found it, framed it carefully: believed to be the first publicly documented malicious MCP server. That is a claim about the state of public reporting, and as such it is very likely correct — no earlier published example has been identified. Downstream coverage drops "publicly documented" and reports it as the first malicious MCP server to have existed. That is a different and unknowable claim. MCP servers are configured locally, often from sources that never touch a public registry, and there is no telemetry that would establish an absence. Recorded because "first" is load-bearing here: it is the reason this incident is cited as a turning point, and the qualified version supports that reading perfectly well without asserting something nobody can know.
Where this claim appeared
The Hacker News · 2025-09-29
https://thehackernews.com/2025/09/first-malicious-mcp-server-found.htmlWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
postmark-mcp: One Line of Code That BCC'd Every Email to an AttackerThink this assessment is wrong? Report an error.