If the USB stick accidentally contains private keys for signing, that might be of concern.
The more important concern is the phishing issue.
The more important concern is the phishing issue.
That would still be a problem if the updates were only distributed to repair shops, however (you'd need someone on the inside, but given the number of people involved, that probably wouldn't be too hard).