based on what is currently known, arch was never vulnerable to the backdoor that was discovered. arch doesn't patch sshd so that it links systemd like how debuntu/fedora do, which was a requirement for the backdoor.
ofc this doesn't rule out any as-of-yet unknown vulnerabilities in xz/liblzma.