Earlier quoted context omitted.
Windhawk mods are distributed as source code and WH itself compiles it. It works the same way usescripts work with tampermonkey/violentmonkey on browsers. If a mod includes malware it'll be very obvious as mods are usually small.
Top tier malware can be incredibly terse and sophisticated. The trigger line to execute the xz exploit was a `.` in a build script. You are probably fine do to sheer obscurity - nerds who yearn for a Win9X experience are low in number and might only be running it for a laugh in a VM.
There's a malware risk in literally every piece of software. Windows itself behaves as malware with all the telemetry it gathers.