Request #86902 has been Accepted by Auerhuhn [1]: At this point, no need to do any more analysis. Three proven malicious PKGBUILDs are enough grounds for assuming that every file the upstream maintainer has ever published can’t be trusted.
[1] https://aur.archlinux.org/account/Auerhuhn/
