If you are working in a shell like that you should have outbound ports locked down and a list of allowed domains set in your proxy. Add in some antivirus and password sudo check and plenty of ways to catch this
Thats why i have a lexical and intermediate representative (IR) code examiner of JavaScript running as an ICAP server capturing all HTTP/HTTPS connections.
This particular attack is actually not a concern if you're using fish (or zsh for that matter I think), as it will not execute pasted content without an additional pressing of the enter key.
It's still a concern because there will be users reflexively pressing enter without checking what they pasted if it's the expected value most of the time.
Meanwhile there is zero benefit for letting websites manipulate the clipboard or intercept basic browser interactions. This might make sense for applications but that's just another argument why those shouldn't be forced into the same browser as websites.
Yeah, I'm disappointed there's no permission toggle so that I could have javascript-based clipboard setting behind a prompt on most websites and have exceptions for others.
Basic malware JavaScript snippet: