There needs to be some way of automatically flagging package upgrades that might be malware.
Introducing calls to things like is system or subprocess should be a red flag.
I feel like the pledge system would be a good model here: https://medium.com/@_neerajpal/pledge-openbsds-defensive-app...