Actually, they could probably use AI to see if each update to a package looks malicious or obfuscated.