The stupid thing is that that it's remarkably easy to sandbox and application these days. Sandboxie is free, though not guaranteed to work (but it may very well have done, or at least would have made the strange behaviour obvious) and Windows Pro has had a right-click menu option to run an executable in a sandbox for a while.
When I read the title, I initially thought it was about infection through IDE ("do you trust the authors of this project" is there for a very good reason and in the case of VS Code attackers can get code execution before the prompt through Git config trickery).
I'd be wary of executing a program, but I bet I would click the "sure enable code execution" button if a recruiter sent me a coding challenge in the form of an incomplete project with a Git repo. Especially if they could set up a remote interview process where they want to go through code live "to see how I approach problems".
Right nowt he attack is super basic, but it's not hard to make the initial infection harder to detect in time.
But what would be even more wicked, and effective would be pointing them to a GitHub repo with the “challenge” project to complete, and referencing a compromised package that does their bidding as the victim tests their solution.
Give me an .exe and ask me to run it, and I'll open it in a hex editor for inspection instead. If what you claim is a "hello world" or Fibonacci generator is much bigger than I'd expect (a few KBs) and contains encrypted-looking data or other attempts at obfuscation, I'm not running it.
Unless you're crafting some revolutionary problem for each candidate, changing details won't matter much.
I’m talking about a take home code challenge. It’s unreasonable to have someone to record a video that could last an hour or more. And I’m not gonna sit and watch that.