It seems the attackers were taking over orphaned packages and claiming themselves as a maintainer, which they were automatically granted after 2 weeks.
Oh yeah. That’s not going to work anymore.
I think it’s just the cycle of enshittification from grifters. Once exploiting an ecosystem is “en vogue” in those malicious actor circles, users kinda just have to lock it down and/or migrate to another, as this is going to keep happening now.
Hence the AUR is not going to run on “reasonable goodwill” anymore. It can’t. That period is over.
I dunno what that means for Arch… maybe better flatpak integration? Or more app packaging in trusted upstream projects (like CachyOS in my case).