1,500 packages out of 107,000 so pretty bad, ameliorated by only affecting installs of those in a window of a few days.
AUR comes with a warning that its up to you to check what you install from there.
I wonder what typical AUR usage looks like. I apparently have 27 packages installed and last updated one in November.
I was concerned at headline, then saw "oh just AUR"
Next up, "millions of malicious packages still not taken down on internet"