I've been freelancing for over a decade. This stuff is every third crypto related job. They're all malware repos running scripts the moment you turn on vscode hoovering up everything they can on your computer.
It's the least surprising thing once you've put yourself out there, very strange watching people here think it's novel, I expect it by default at this point, a stranger handing you code needs to go into a vm, would you let them hand you some candy with a wink too?