Hi. This might all ready exist, but is there a list of previously submitted malicious packages? We track installed packages, and it would be of interest to be able to compare our list to malicious packages that have made it into production so that we could address them and remove them.

This has been requested before, e.g.

There is an open issue to do this…

Which then evolved into this proposed approach for handling it:

