A developer built trust over 15 legitimate-looking versions of an npm package impersonating Postmark’s official MCP server, then published a version 1.0.16 on September 17, 2025 containing a backdoor that silently forwarded a blind copy of every email sent through the server to an external address. The package, downloaded roughly 1,643 times before removal, exposed password resets, invoices, customer data, and internal correspondence from organizations that had integrated it as a routine dependency.