Gist: A malicious npm package impersonates Postmark, steals email data, and is unrelated to the company’s official API or services. The notice warns users to remove the fake package, review logs, and rely only on documented official resources.
Signal reason: It reinforces the brand’s trust and security positioning around official APIs and resources.
