Blender is a widely used open-source 3D creation suite for modeling, animation, and asset development.
Blender is a technology platform tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity December 10, 2025.
Blender is a widely used open-source 3D creation suite for modeling, animation, and asset development. Recent reports show attackers embedding a stealer in Blender model files to deliver the StealC infostealer, illustrating a file-based attack surface within Blender assets and distribution channels. This underscores the cybersecurity risk to individuals and organizations that download, share, or rely on Blender models from untrusted sources.
A Russian-linked campaign is distributing the StealC V2 infostealer malware through malicious Blender 3D model files uploaded to marketplaces like CGTrader. This malware exploits Blender's ability to execute Python…
Blender is a widely used open-source 3D creation suite for modeling, animation, and asset development.
The most recent intelligence report mentioning Blender on ThreatCluster is dated December 10, 2025. Activity was first observed November 24, 2025, giving a tracked span from then to December 10, 2025.
Across ThreatCluster reporting, Blender most frequently co-occurs with Malware, StealC, T1059.001 - PowerShell, T1059.006 - Python, CGTrader, among 9 tracked related entities.
The most significant recent cluster is “StealC Malware Spread via Malicious Blender 3D Model Files” (2 articles · Updated December 10, 2025). Blender appears across 1 threat cluster in total, listed above with sources.
Blender appears in 2 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.