I don't mind malware being lumped in to that - the place to look up code for historical or analysis reasons ought to be version control, not crates.io
The build infrastructure should make security incidents easier to respond to, not harder. I shouldn't be sent on a wild goose chase at a time when I'm potentially already dealing with a major incident. The tools need to "just work".