My initial thoughts as well.. have been playing with development inside containers, and this just makes me sure I need to do it much more. Also, pushing for read-only containers in production for most things, along with running as a non-privileged user.
Unless your program is a black box that doesn't interact with the rest of the world in any way, sandboxing will not be enough. People still need to mitigate the effects of malicious supply chains.
This may protect your computer, but not visitors of your site using malware npm module on front end.
that is the job of browser vendor to sandbox on the front-end side