upvote
I was concerned at headline, then saw "oh just AUR"

Next up, "millions of malicious packages still not taken down on internet"

reply
I wonder what typical AUR usage looks like. I apparently have 27 packages installed and last updated one in November.
reply
There's more than one way but this lists packages not installed by pacman itself:

    pacman -Qm
Only 237 on my 12 year old system but I rarely update AUR packages and usually try to remove unused ones before updating.
reply