I think I escaped it because I use Garuda. They have their own copy called Chaotic-Aur where they prebuild and scan stuff. Between that layer, and me being slow to update, according to the scan, I avoided it. The packages that were infected that I had installed were older copies from before the infection.
After the AUR debacle, I'm considering it.
Compile your malware from source, like a real engineer!
I think I escaped it because I use Garuda. They have their own copy called Chaotic-Aur where they prebuild and scan stuff. Between that layer, and me being slow to update, according to the scan, I avoided it. The packages that were infected that I had installed were older copies from before the infection.
Try it, you start by installing it from chroot, so there's nothing to lose.
It's very good, though I don't use a full DE, so my compile times may not be representative.
Just don't download anything stupid from AUR. Verify your getting the correct, supported packages, and you should be fine.