This document presents a framework called OSSCR that aims to evaluate open-source software packages and measure potential supply chain risks. The framework was developed by studying over 650 previously documented malware samples found in open-source packages. Key attributes that make packages vulnerable, such as inactive maintenance, sensitive OS functionality combined with network access, and social engineering attacks are used to flag packages as potentially risky. The goal of the OSSCR framework is to help developers identify and review supply chain risks in open-source packages before using them.