Check this to be (more) sure:
https://github.com/lenucksi/aur-malware-check
(And obviously don’t trust me either, check the .sh with your eyeballs too).
Amongst other things, it checks the history of your installs/uninstalls, so takes the date into account. Hence I had installed graalvm, but fortunately it was never updated in the compromised window.