Skip to main content
Reported, primary not reachedExfiltration

A cloned MCP server silently copied every email agents sent through it

A developer cloned a vendor's official MCP email server, published it under a similar name, shipped fifteen clean versions, then added one line that blind copied every message an agent sent to an address he controlled. Agents kept sending password resets and internal notices, with a copy going elsewhere. The research blog that first documented it is no longer served.

The verdict

Reported, primary not reached

A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.

Key facts

What the sources say

Record ID
AIL-2026-0015
Kind
Exfiltration
Jurisdiction
Global
Last verified
Added
  • The Register reports that a backdoored version added a blind copy of every message to an attacker controlled address.
  • The package had run through more than fifteen clean releases before the line was added, so a version pin would not have looked suspicious.
  • The copy was invisible at send time, so neither the agent nor the operator saw a second recipient.
  • The package was removed after the publisher was contacted, rather than by any platform control.
  • The original research post now redirects to an unrelated vendor page, so this record carries no primary source.

Dimension by dimension

6 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Logging and audit, Human approval, Revocation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
The MCP server inherited the sending identity of the organisation with no principal of its own.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
AuthorizationSilent
The tool's declared function and its real function diverged, and nothing checked the difference.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
LimitsSilent
No restriction existed on where a message the agent sent could be addressed.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
Logging and auditSilent
The copy was silent to the sender, which is the whole point of the attack.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
Human approvalSilent
The extra recipient was never presented for approval because it was never displayed.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.
RevocationOpen
The package was pulled, but by the publisher rather than by a platform control that noticed anything.The Register, Postmark MCP server code hijacked, secondary source, 29 September 2025.

Figures

Every number, with who measured it and when

  1. 15,000 emails per day

    Emails copied per day at the top of the range the research printed

    The Register, Postmark MCP server code hijacked, secondary source, as of .

What it changes

For a team deploying an agent

An MCP server is code you install with your agent's authority, and a name that looks official is not provenance. Pin versions, review the diff on every upgrade of a server that can send or write, and route agent email through your own infrastructure so the recipients appear in a log you own. Logging is the control that would have caught this on day one.

Sources

What this record was verified against

  1. The Register, Postmark MCP server code hijackedSecondary · 29 September 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0015 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), a cloned mcp server silently copied every email agents sent through it.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A cloned MCP server silently copied every email agents sent through it. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email
MLA
"A cloned MCP server silently copied every email agents sent through it." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email.
Chicago
GAGE (Global Academy of Generative-AI Education). "A cloned MCP server silently copied every email agents sent through it." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0015-postmark-mcp-backdoor-copied-every-agent-sent-email

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for Global and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.