Gist: A malicious npm package impersonates Postmark, steals email data, and is unrelated to the company’s official API or services. The notice warns users to remove the fake package, review logs, and rely only on documented official resources.
Signal reason: The content describes a malicious package stealing emails and advises remediation steps.
