That is what the tj-actions attacker did: https://unit42.paloaltonetworks.com/github-actions-supply-ch...