I recently wrote about an RCE exploit in the game Project Zomboid (which uses Lua for mods), which also used loadstring as an initial entry point for the exploit chain, but since the Lua interpreter was fully Java, byte-code memory manipulation shenanigans were out of the question for me and I had to pivot in a more traditional way.
The fact that loadstring can also load straight up bytecode was news to me though, that's interesting to know.