Many CI server configurations will rely on running jobs under a role which can only assume other roles. Individual jobs will then assume the role they need.
Something like this infecting a popular Node.js / Python / Ruby package could potentially do a lot of damage.