What would the input to such a model be? The malicious code snippets?
Or do you want to classify packages according to other meta data?
I think certain things would be picked up pretty easily e.g. obfuscated code would be a pretty loud feature, but subtle stuff might be undetected and generally I can't see the model being super accurate.