Sure but that's a one time vector. If the attacker didn't infiltrate the LLM before it generated the code, then the code is not going to suddenly go hostile like an npm package can.
Though you will see the code at least, when you are copy pasting it and if it is really only a few lines, you may be able to review it. Should review it of course.
I did not say to do blind copy paste.
A few lines of code can be audited.
... and now you've switched the attack vector to a hostile LLM.