No, the above attack writes that function into bashrc, meaning the next time the user runs sudo themselves, you harvest their password.