Pfft malware on desktop linux isn't new, Ubuntu has been shipping snaps for a while now /j
To be fair, the AUR is 'use at your own risk' and you can see who is maintaining the package, and the packages they maintain. Some of these maintainers maintain 20+ packages.
Pfft malware on desktop linux isn't new, Ubuntu has been shipping snaps for a while now /j