Replying to
@mttaggart@infosec.exchange Antonio Rojas is a member of Arch Linux and a year-long package maintainer of the distribution (e.g. for all of KDE).
Antonio often drops larger amounts of packages to the AUR and therefore is the last committer.
The bot infecting packages in the AUR impersonated/reused the last committer. It's trivial to do with git.
I know this is not directly obvious, but please correct previous statements about this (also made elsewhere). 🙏