Looks like the Arch Linux AUR (Arch User Repository) needs some better security and package checks - as some malicious users ...
A wave of malicious commits hit the Arch User Repository (AUR) over the weekend, prompting the team to disable new account ...
Arch Linux defends itself against a wave of attacks that have massively contaminated package descriptions in the unofficial Arch User Repository with malware.