Those headlines were the usual "mention (seemingly) big numbers without context"-bullshit. You can easily look up the actual amount of packages in the AUR...
They also did not "inject malicious code into AUR packages" because of some insecurity that needed fixing. They simply took over orphaned packages then modified them.
So actual reality boils down to:malicious actors took over a miniscule amount of AUR packages with so little public interest nobody even maintained them. And the AUR is as secure as it ever was. Which means not very secure at all because it's public community content without any vetting. So look up the package and actually read the PKGFILE. Just as Arch is vocally warning you.
99.9% of changes are version numbering, checksum and rarely slight dependency changes. There is no chance anyone affected by a long orphaned package that got taken over and modified did ever read that one stupid file of just a few lines (or just the dif provided by several AUR helpers automatically).


Und was sind die großen Anwendungsgebiete für moderne Batterien? Oh... die Autoindustrie, tragbare Elektronik und das Stromnetz. Also wurde politisch gezielt dafür gesorgt, dass es hier kein Anwendungsgebiet gab, und VARTA hat fröhlich weiter altertümliche Bleibatterien produzieren können.