packj: detect malicious/risky open-source software packages

risky open-source software packages