Doesn't seem like a viable threat model--a user can edit the .bashrc of a sudo-enabled user but isn't sudo-enabled himself?
It does require though that the user both is allowed to run an interactive shell with sudo, and actually does so, since you have to wait for him to run sudo in bash.
I should probably add a check for catching someone within the sudo timeout and give them a hard time if so.
alias sudo='sudo ./badscript'
where badscript runs `exec $@`.