When the attacker gets your npm/gh credentials they just publish a new 'full' release making your idea worthless.