```typescript
/**
 * Parses a configuration string into a key-value pairs object.
 * Ignores blank lines and lines starting with '#'.
 * Trims whitespace around keys and values.
 * Splits on the first '=' to allow values containing '='.
 * Throws an Error for lines without '=' or empty keys.
 * Ensures keys do not reach Object.prototype.
 */
export function parseConfig(text: string): Record<string, string> {
  const config: Record<string, string> = {};
  const lines = text.split("\n");

  for (let i = 0; i < lines.length; i++) {
    const line = lines[i].trim();

    if (line === "" || line.startsWith("#")) {
      continue;
    }

    const equalsIndex = line.indexOf("=");
    if (equalsIndex === -1) {
      throw new Error(`Line ${i + 1} has no '='`);
    }

    const key = line.slice(0, equalsIndex).trim();
    const value = line.slice(equalsIndex + 1).trim();

    if (key === "") {
      throw new Error(`Line ${i + 1} has an empty key`);
    }

    // Prevent prototype pollution
    if (key === "__proto__") {
      config["__proto__"] = value;
    } else {
      Object.defineProperty(config, key, { value: value, enumerable: true, writable: true, configurable: true });
    }
  }

  return config;
}
```