Few months ago I switched to using an alias of parur='paru -Syu --repo'; so I still update frequently with that command that excludes AUR updates as usual and fortunately I was not hit with this AUR attack
I occasionally try normal paru (-Syu) to get AUR updates sync but even then I mostly update each package at a time as need arises for them, for example if something broke because of core package dependency updates.