Blender MCP Maintainer Loses Control of 25k-Star Repo After GitHub Account Takeover
Siddharth Ahuja reported on August 9 that his GitHub account was compromised and his ownership rights stripped from Blender MCP (25,000 stars) and Ableton MCP (2,600 stars) along with personal projects, with the account suspended while the attacker pushed commits to the repositories. The incident lands amid a broader pattern of threat actors compromising maintainer accounts to publish infected package versions across npm, Packagist, Go modules and Chrome extensions, often via account-recovery abuse or expired-domain vectors. Two separate CVEs (CVE-2026-10661 and CVE-2026-10662) were also filed against ahujasid/blender-mcp; anyone running MCP servers pulled from GitHub should pin commits rather than track branches. Note: the takeover itself is currently sourced to the maintainer's own account.
↳ Follow the thread