I agree with @Lockdown that disabling PowerShell is generally a good idea (H_C recommended settings block PowerShell sponsors on all WIndows versions prior to windows 10).
Yet, the malware which is running as standard user (not elevated) cannot change the Language Mode, neither by PowerShell commands nor by the reg tweak.
Can Constrained Language Mode be bypassed for malicious tasks? Yes, there are some (not easy) ways.
PowerShell Constrained Language Mode is OK when used with default-deny setup.
Yet, the malware which is running as standard user (not elevated) cannot change the Language Mode, neither by PowerShell commands nor by the reg tweak.
Can Constrained Language Mode be bypassed for malicious tasks? Yes, there are some (not easy) ways.
PowerShell Constrained Language Mode is OK when used with default-deny setup.