

The script in the top post of this thread does a better job, since it actually checks when you have upgraded the affected packages: https://discuss.cachyos.org/t/aur-compromised-1500-packages-affected-20260611/31040
There’s also an even more thorough https://github.com/lenucksi/aur-malware-check








have you considered fucking not?