The fact
Packages were compromised to inject malicious code.
The initial announcement was made on July 30 by an official contributor.
Click the link to read an article on the topic:
Why it matters
Les utilisateurs d’Arch Linux doivent vérifier l’intégrité des paquets AUR et privilégier les sources officielles pour éviter les infections.