I'm afraid a few simple tweaks, especially if the hackers themselves have access to the code LLM to try out their code, will be sufficient to evade detection.
Endless race like with Anti-Virus software.
I have a feeling that we'll be seeing some businesses, built, around exactly that.
Github? ;)
Socket.dev is not built around this but makes use of this.
If such a tool became commonplace, bad actors would just run it on their own malware and keep tweaking it until the LLM failed to detect it.