Hi.
I have a similar situation. Yesterday I received a private request "Our company is looking for partners to work on an ambitious project." $4000
A strange description, without a specific task and reference pictures, only they attached a blend file as an example of the work they want to receive
I was saved by the fact that when opening the blender file there was a warning about a python script that could do harm, I launched the file without turning on the script, there was only a chair (although they asked for a character project)
Be careful if you have automatic script loading configured in your blender!!!
In general, I'm not 100% sure that there is malicious code there. If someone knows how to safely check the blender file and the script in it, I would be interested in what kind of script is there and what to be wary of.