That's not true, I'm quite sure most repos on GitHub have neither many stars, nor forks, nor multiple contributors.
Please never rely on any such "social" metrics.
Nothing might happen but you should be on the alert.
That by itself should have been the first red flag. I also heard a lot of these stories recently. I think this might be one of the good use cases of GitHub Codespaces.
I was never asked to install anything. I was not even given code access (without NDA) and I did get paid with equity/money in cases there was a mutual match and we proceeded.