If you let malicious code run unsandboxed on your main account then you probably have bigger problems than an OpenAI API key getting leaked.

You mean running npm update at the "wrong time"?

[deleted]