Yeah, I’ve cleared out my AUR packages after the first hack.
It’s not worth the risk. Just like I don’t keep npm installed on my machine.
AUR’s period of altruism is over. The cat is out of the bag. Scammers are onto this trend, so now they’re going to keep on hacking AUR accounts in perpetuity.
…In fact, I think AUR needs a dramatic overhaul, or even a depreciation, as its security model just isn’t viable anymore. And Arch (the organization) is in the hook for incidents like this, as the AUR is hosted in archlinux.org.