strong disagree. it's very similar to anti-phishing training/tests. also, being tagged as a company that cares that its potential new hires are not lazy programmers that just copy&paste because someone told them too would more than likely be taken as a positive not a negative.
Will there be trap clauses in the NDA and contract to see if they carefully read every line ? Will they be left with no onboarding on day one to see how far they can go by themselves ? etc.
You're starting the relationship on the base of distrust, and they don't know you, they have no idea how far you're willing to go, and assuming the worst would be the safest option.
That was an innocent canary clause (they were not asking to put the POS on fire)
The equivalent here would be to ask the candidate to have some folded paper showing his name on camera for the interview, not threatening them with malware.
Competent candidates might also disqualify you as employer right there. Plus you'll be part of normalizing hazardous behavior.