AUR was considered a looming security threat.
Malicious apps got into the Arch User Repository - how to protect yourself ...
I've run Arch nine different ways, BTW.
Attackers hijacked over 1,500 packages in Arch Linux's AUR to plant a credential stealer. The official repos are safe, but the trust model took the hit.
3 ways the new Steam Machine could be a huge win for Linux ...