Any of you seen the news about php-pear? There's an AUR package that downloads from pear.php.net so if that was within the last 6 months it could have been the compromised one? https://thehackernews.com/2019/01/php-pear-hacked.html