Web3 and blockchain developers should never run source code that is sent to them with the promise of a pre-interview, whether via social media, GitHub profile or company profile that is 100% trustworthy. Otherwise, Web3 wallets could be at risk. NPM and NuGet packages may contain packets encrypted with human-readable encryptor (HRE) algorithms, where letters that the human eye cannot detect but the brain can read correctly are replaced.
For this reason, it is important to always obtain source code from sources you trust and verify. Running code from untrusted sources can pose a serious security risk.