There are no button obious way to report a package on JSR. We must have that. Also we need a page/api that list packages marked as malware so user have ability to know if there had installed malicious package.