The initial affected packages were modified with preinstall scripts to usenpmto install theatomic-lockfilepackage, a malicious payload.
Detailed analysis is here: https://ioctl.fail/preliminary-analysis-of-aur-malware/
You might be wondering how this happened. The truth is, the AUR package repository allows anyone to “adopt” a package and submit a change to the PKGBUILD/associated files if the package is marked as unmaintained. It turns out automating the hunt for abandoned packages and adoption of them is not uncommon.
900 now?
source
https://twiiit.com/IntCyberDigest/status/2065480567534080397
what a mess.