A cloned MCP server silently copied every email agents sent through it
A developer cloned a vendor's official MCP email server, published it under a similar name, shipped fifteen clean versions, then added one line that blind copied every message an agent sent to an address he controlled. Agents kept sending password resets and internal notices, with a copy going elsewhere. The research blog that first documented it is no longer served.
The verdict
Reported, primary not reached
A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.
Key facts
What the sources say
- Record ID
- AIL-2026-0015
- Kind
- Exfiltration
- Jurisdiction
- Global
- Last verified
- Added
- The Register reports that a backdoored version added a blind copy of every message to an attacker controlled address.
- The package had run through more than fifteen clean releases before the line was added, so a version pin would not have looked suspicious.
- The copy was invisible at send time, so neither the agent nor the operator saw a second recipient.
- The package was removed after the publisher was contacted, rather than by any platform control.
- The original research post now redirects to an unrelated vendor page, so this record carries no primary source.
Dimension by dimension
6 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Logging and audit, Human approval, Revocation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- The MCP server inherited the sending identity of the organisation with no principal of its own.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
- AuthorizationSilent
- The tool's declared function and its real function diverged, and nothing checked the difference.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
- LimitsSilent
- No restriction existed on where a message the agent sent could be addressed.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
- Logging and auditSilent
- The copy was silent to the sender, which is the whole point of the attack.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
- Human approvalSilent
- The extra recipient was never presented for approval because it was never displayed.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
- RevocationOpen
- The package was pulled, but by the publisher rather than by a platform control that noticed anything.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
Figures
Every number, with who measured it and when
- 15,000 emails per day
Emails copied per day at the top of the range the research printed
The Register, Postmark MCP server code hijacked, secondary source, as of .
What it changes
For a team deploying an agent
An MCP server is code you install with your agent's authority, and a name that looks official is not provenance. Pin versions, review the diff on every upgrade of a server that can send or write, and route agent email through your own infrastructure so the recipients appear in a log you own. Logging is the control that would have caught this on day one.
Sources
What this record was verified against
- The Register, Postmark MCP server code hijackedSecondary · 29 September 2025
Related
Records that sit beside this one
Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
Global · verified 15 September 2026
The Nx postmortem states that on 26 August 2025 malicious versions of several Nx packages were published to npm.
A widely installed documentation MCP server carried a prompt injection into connected coding agents
Global · verified 15 September 2026
The CVE record states that the product contains a prompt injection allowing attackers to execute malicious instructions in connected AI coding agents.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0015 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), a cloned mcp server silently copied every email agents sent through it.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). A cloned MCP server silently copied every email agents sent through it. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email
- MLA
- "A cloned MCP server silently copied every email agents sent through it." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "A cloned MCP server silently copied every email agents sent through it." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.