Ok, lets consider the authors example of SuperTinyIcons (https://github.com/edent/SuperTinyIcons). What are some possible ways you could send a PR, gain commit rights and then use it for compromising security?
For what benefit? Infecting a few dozen probably fairly small sites while ruining the credibility of the contributor’s account? It’s extremely obvious and would pretty quickly get caught, even if the article author doesn’t keep too close a tab on the repo.