Yes, that's one of the method that was used:
from https://news.ycombinator.com/item?id=9284226 :
> The first round was cross-domain JavaScript, stopped with an "alert()". Second round was cross-domain <img>, stopped with referrer. Third was DDoS-ing GitHub Pages. Fourth is the ongoing TCP SYN Flood attack.