Interesting, I prefer Flatpak over the AUR when available, because the AUR seems more susceptible to attacks like this. I don't know the security model of a Flatpak repository, so it's just a feeling so far.
To the person(s) down voting this, please speak up about why. Let's have a discussion, or maybe teach me something! 😃👍