Earlier quoted context omitted.
It's still surprising someone was able to infect so many packages. But I admit I don't really know how AUR works. Can anyone with access simply update anything? Do packages not have owners who check contributions?
Packages in the AUR have some number of maintainers. When a maintainer no longer wants to maintain the package they can disown it, and when all maintainers do so the package becomes orphaned. An orphaned package can then be adopted by any user. At any time there's a large number of orphaned packages in the AUR, and the attacker(s) targeted those.
Who needs social engineering NPM maintainers when there are thousands of freebie AUR ones.