@zekjur well there ya go. You put the entire code of your malicious repo in the commit message and just put decoy code as the repo src.