I wrote a Docker-based sandbox [1] for myself last year to control the blast radius of such malicious packages.
https://github.com/ashishb/amazing-sandbox