It appears, however, that the developer took the legitimate code from the Postmark MCP server's GitHub repository, added the ...
According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called " ...