One thing I've always thought would be a good idea is a tool (either local or part of the pip/other packet manager download process) that greps and prints out all URLs and IP addresses within the code, including common encodings. Additionally, any lines that uses any transfer protocols (like HTTP requests) should be highlighted too as IP/urls can be encoded. Any HTTP request, for example, to suspiciously encoded URLs could raise flags.
The official library itself could have a "urls" file which has a list of urls that are expected and so anything that doesn't match can be questioned.
Whilst this won't solve the issue 100%, it raises the difficulty barrier to implement outgoing network calls.