4 comments

  • toomuchtodo 20 hours ago ago

    > PSA: Declare an incident if someone on your team installed the postmark-mcp on their machine.

    > All your emails had a secret BCC added to them since version 16.

    https://www.koi.security/blog/postmark-mcp-npm-malicious-bac...

  • chrisandchris 15 hours ago ago

    > [...] and published it to npm under the same name.

    We have seen thes so many times, and still do not want to do _anything_ against this attack vector. So sad to look at.

    • cyanydeez 15 hours ago ago

      Id say LLMs are the generic attack vector.

      • chrisandchris 4 hours ago ago

        No, npm allpwing account takeovers and re-using package names like it's sharing a sandwich, that's the issue. This problem exists longer than the word "LLM".