Or maybe it's easier to set up a bot to scrape PIP and look for small edit distances in package names for popular projects, and setting up some features for what be a malicious packages: (1) small amount of content, (2) duplicated content with minor changes, (3) small number of commits for the backing repo as reported by pypi's metadata, (4) invalid setup.py metadata, (5) duplicated metadata from another package, (6) newness on pypi