This is definitely pretty strange. Account takeovers happen, but just reverting the commit and closing the issue after one gets discovered is not the best way to handle these.
This is the reality of our modern software development process though. Your threat model now must include the GitHub account of every maintainer of every open source project you use.