none of the affected packages were popular and iirc all were flagged out-of-date for a long time, which is also why the attackers got access as they were abandoned.
just review pkgbuilds and pay attention to ones that get flagged out-of-date when you're updating and go check it out and find an alternative if the upstream project looks abandoned as well or install it from source instead if it's just the aur pkg.
most out of date aur pkgs i've had ended up being things that the arch team put in extra so i just needed to install that one instead anyway.