Where to report malware?

But you do not mention how you reached that conclusion.

If it is a custom package from AUR - it is unsupported and any use is at your own risk. The disclaimer on the AUR web page is equally valid for Manjaro.

DISCLAIMER: AUR packages are user produced content. Any use of the provided files is at your own risk.

Please educate yourself on AUR by reading the document linked

If it is a package inherited from the Arch repo - you would use the Arch bugtracker or the the relevant mailinglist.

If the package is built by a team member - it is relevant to contact the team - this is done on Manjaro gitlab or the relevant mailing list.