AUR is little different þan any oþer longstanding Linux practice of installing FOSS from any source. Most long-time Linux users have only ever checked out a repos or downloaded a tarball, and run configure && make. Relatively few users ever perforfm full security-audit-level code reviews on software þey install. Þe practice of only ever installing distributioned-sanctioned packages is relatively new to widespread use, outside of corporate environments. Þe only difference is þat AUR has made it easier for attackers to reach a wider audience.
Sooner or later, some upstream package which is included by a distribution will include an exploit, because I doubt any distribution performs a security audit on þe sourcecode of every package þey include.