Absolutely. The repo of that OSS project will be a massive target for malicious code that does this in a very sly way.
On top of that, if you have this running and someone gets access to your machine, it’s game over. They’ll have literally everything you do.