On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits