Investigation will determine whether the Blender MCP maintainer’s GitHub account compromise produced malicious commits, releases, or other downstream supply-chain impact for users.
state: expiredheat: mediumuncertainty: highknownscott: lowmcp-security software-supply-chain maintainer-account-compromiseBlender MCPsidahujGitHub
What is this?
A report alleges that the GitHub account maintaining Blender MCP was compromised, raising the possibility that an attacker could have introduced malicious commits, releases, or other changes affecting users of the MCP integration. The supplied material does not establish whether the named maintainer account (“sidahuj”) was actually compromised or whether any Blender MCP artifact was altered or distributed; no downstream impact is confirmed. The other search snippets document broader GitHub credential-theft and supply-chain campaigns, but they do not directly connect those campaigns to Blender MCP.
Why it matters to Scott
Scott already holds the relevant position in “Agent Provenance Stack” and “MCP as the Tool Belt Standard”: MCP tools and updates require verifiable artefact provenance, signing, least privilege, and containment because maintainer identity alone is not a sufficient trust boundary. The unresolved Blender MCP allegation is currently only another possible example of that established threat model; without confirmed malicious artefacts or downstream impact, it does not yet change what Scott should build or argue.
ip:source.agent-provenance-stackip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:concept.cryptographic-trustradar:concept.mcp-securityradar:concept.software-supply-chainradar:concept.open-source-maintenance
queries asked of Scott's wikis
- MCP server trust boundaries and security model
- agent tool installation and update risks
- maintainer compromise in AI tooling dependencies
- provenance and signing for MCP servers
- sandboxing high-privilege agent integrations
- software supply-chain controls for coding agents
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-12T02:29:26Z
After 48 hours, no independent confirmation, altered artifact, affected release, or downstream impact has emerged; the allegation has faded without developing into a substantiated supply-chain incident.
2026-08-10T01:34:06Z
Re-observation adds no corroboration or evidence of altered artifacts, releases, or downstream impact; the case remains an urgent-to-monitor allegation rather than an established supply-chain incident.
2026-08-10T01:31:41Z
grounded: known/low — Scott already holds the relevant position in “Agent Provenance Stack” and “MCP as the Tool Belt Standard”: MCP tools and updates require verifiable artefact pro
2026-08-10T01:29:08Z
case created — An apparently active maintainer-account compromise could have immediate MCP supply-chain consequences and warrants rapid re-observation.
Decision trace
- 08-12 12:29expireAfter 48 hours, no independent confirmation, altered artifact, affected release, or downstream impact has emerged; the allegation has faded without developing into a substantiated supply-chain inciden
- 08-12 12:29alert_silentThe only change is elapsed time without new evidence; engagement and a hot topic neighbourhood do not justify further attention absent confirmation of compromise or affected artifacts.
- 08-12 12:29alert_routeThe only change is elapsed time without new evidence; engagement and a hot topic neighbourhood do not justify further attention absent confirmation of compromise or affected artifacts.
- 08-10 13:21sensor_dirtyengagement_update
- 08-10 11:34repriceRe-observation adds no corroboration or evidence of altered artifacts, releases, or downstream impact; the case remains an urgent-to-monitor allegation rather than an established supply-chain incident
- 08-10 11:34alert_silentThe only visible delta is an unchanged repetition of the original claim, with no independent confirmation or actionable artifact; it can wait unless compromise evidence or affected releases emerge.
- 08-10 11:34alert_routeThe only visible delta is an unchanged repetition of the original claim, with no independent confirmation or actionable artifact; it can wait unless compromise evidence or affected releases emerge.
- 08-10 11:32alert_silentOnly a repeated, uncorroborated report of account compromise is visible; there is no confirmed malicious commit, release, credential use, or downstream impact, and no new protective action beyond Scot
- 08-10 11:32alert_routeOnly a repeated, uncorroborated report of account compromise is visible; there is no confirmed malicious commit, release, credential use, or downstream impact, and no new protective action beyond Scot
- 08-10 11:31groundScott already holds the relevant position in “Agent Provenance Stack” and “MCP as the Tool Belt Standard”: MCP tools and updates require verifiable artefact provenance, signing, least privilege, and c
- 08-10 11:29createAn apparently active maintainer-account compromise could have immediate MCP supply-chain consequences and warrants rapid re-observation.