ThreatPaper
Unverified

The attacker built trust over 15 versions before adding the backdoor

Assessment

The framing describes a patient adversary establishing credibility before striking, and the dates do not support it. The package was first published to npm on 15 September 2025. The backdoored version 1.0.16 was released on 17 September 2025. Fifteen versions across roughly two days is rapid iterative publishing — the ordinary churn of getting something working — not credibility accumulated over time. The version count is real; what is unsupported is what it is taken to mean. "Fifteen versions" reads as duration to anyone who does not check the dates, and every account of this incident repeats it without them. The distinction changes the defence. A patient adversary is countered by treating new maintainers with suspicion over months and watching for a change in behaviour. A package that goes from first publication to backdoor in two days is countered by not adopting two-day-old packages — a far simpler control, and one that would have excluded this entirely. Rated Unverified rather than False because no source states a duration outright; the implication is carried by the phrasing. The record supports "fifteen versions", and does not support what most readers will take from it.

Where this claim appeared

Postmark · 2025-09-25

https://postmarkapp.com/blog/information-regarding-malicious-postmark-mcp-package

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

postmark-mcp: One Line of Code That BCC'd Every Email to an Attacker

Think this assessment is wrong? Report an error.