https://aur.archlinux.org/cgit/aur.git/tree/x11-qemu-validation.install?h=x11-qemu-validation
The package names itself for validating qemu config, but from the postinstall script, it does the following 1. add a sudo user with hardcoded password 2. installs, enables and starts sshd with "PasswordAuthentication yes" and "PermitRootLogin no" It's simple script but what it claims to do (validation of x11 or qemu) has no relation to what it does (creating a backdoor). Therefore I think is package is likely malicious, and I doubt whether this AUR user can be trusted.
