even if they could change the receive address, they have to change also the signing hash, that is coming only from your wallet you used. So in this case is useless for them, they cannot sign a tx that do not have the keys... only from their own address...
TLDR