The attacker doesn't publish it untill he has enough transactions referencing the second doublespending transaction.
The second doublespending won't be referenced because the longest tip already contains the legit transaction.
Anyhow, we are discussing now with CfB ways to define better referral algorithms, which would permit to fence off such attacks in a more efficient way.