The situation was under control within the day it was reported. The window where you could've been affected was only a few hours. It was not a case of them "uncovering" thousands of infected packages that were lying around for months. They were noticing an automated attack of hijacking and infecting orphaned packages as it was happening and rushing to keep up while warning the public.
That's not to say the AUR is "safe". Its as safe as its always been. Continue to read your PKGBUILD diff's as you always should have.