I once experimented with a Tor router on a VM that isolated another VM's internet connectivity.
The idea was |Stealth VM| --> |Tor router VM| --> |Virtual Box NAT|
The Tor router VM was running redsocks[0] to route all TCP traffic through tor's socks proxy interface. The stealth VM also used tor's DNS service.
That way, even if the stealth VM is compromised, it can't access the internet directly.