The first-ever malicious Model-Context-Prompt (MCP) server, a trojanized npm package named `postmark-mcp`, has been discovered exfiltrating sensitive data from users’ emails. The package copied every email processed to a server controlled by the attacker.
   
    
 
 
  
   
   A malware botnet called Ebury is estimated to have compromised 400,000 Linux servers since 2009, with over 100,000 still compromised as of late 2023. The findings come from cybersecurity firm ESET, which characterized it as one of the most advanced server-side malware campaigns for financial gain.