Malicious MCP Server on npm (Sep 2025) — The first confirmed in-the-wild malicious MCP server impersonated "postmark-mcp" and secretly BCC'd every outgoing email to the attacker for weeks.
Source: Koi Security Research, Sep 2025Supply Chain Vulnerabilities