My choice? I would run everything in a docker container and have the container routinely rotated. I would run that container within a secure OS - behind a dedicated firewall.
My knowledge would allow me to run this all on a number of platforms because I know this area.
Maybe I am misunderstanding your question.
Are you wanting to secure your own JS on your own server, or wanting to secure yourself from rogue scripts on systems you connect to as a user?
If it is the second one and your existing machine doesn't work for qubes (or you don't have dual boot available or anything) then I would install tails on a usb stick and boot into that or run tails on a raspberry pi or similar and remote desktop to that for all of your insecure testing. That way every time you reboot, you zero whatever was done, so even if you do compromise the machine with a bad actor link, you reset it as soon as it restarts.