Create a CRD that registers a conversion webhook pointing at an attacker-controlled server.
Every read and write of that custom resource type is routed through the webhook, which can read and rewrite objects in flight.
The API server requires a CA bundle and TLS, so this needs a serving certificate the API server will accept.
