The attacker had permissions to create GitHub releases, so they simply added it to the GitHub release tarball.
The attacker had permissions to create GitHub releases, so they simply added it to the GitHub release tarball.