postmark-mcp: The First Confirmed Malicious MCP Server Found in the Wild
A single added line of code in a compromised npm package silently BCC'd every outgoing email to an attacker. Snyk's disclosure marks the first real, deployed malicious MCP server, not a proof of concept.