I want the OS to have a permission where the app can do things when I have it closed. For 99% of the apps I use, I'd turn that off. I don't need them doing any shit in the background.
While it could open you up to some nefarious activity, it may not that in and of itself. You said you had copied code; any chance the code contained a redirect or a call that opened up a reverse shell? Did you scrub the code first? Does your IDE run sandboxed? Is it possible to run your IDE In a VM removed from your host OS - if your network connection is active and bridged in a VM, you could still be open to catch some shit.
(post is archived)