

Mozilla warns of phishing attacks targeting add-on developers
By
Sergiu Gatlan
- August 4, 2025
- 06:00 AM
- 0

Mozilla has warned browser extension developers of an active phishing campaign targeting accounts on its official AMO (addons.mozilla.org) repository.
Mozilla’s add-on platform hosts over 60,000 browser extensions and more than 500,000 themes used by tens of millions of users worldwide.
According to Mozilla’s advisory, these phishing emails are impersonating the AMO team and claim that the targeted developer accounts require updates to maintain access to development features.
“The developer community should be aware we’ve detected a phishing campaign targeting AMO (addons.mozilla.org) accounts. Add-on developers should exercise extreme caution and scrutiny when receiving emails claiming to be from Mozilla/AMO,” Mozilla cautioned on Friday.
“Phishing emails typically state some variation of the message’ Your Mozilla Add-ons account requires an update to continue accessing developer features.’”
ADVERTISEMENT
SCROLL TO CONTINUE READING
To secure their accounts, developers are advised to always verify if emails they receive are sent from a Mozilla domain (firefox.com, mozilla.org, mozilla.com, or their subdomains), that they pass standard email authentication checks (including SPF, DKIM, and DMARC), and not to click on links embedded in suspicious emails.
Mozilla also urged developers to navigate directly to its websites rather than following email links, and only enter their login credentials on official Mozilla or Firefox domains.

Mozilla phishing email (Juraj)
While Mozilla has yet to disclose the scale of this phishing campaign, the end goal of the attacks, or whether any developer accounts had already been successfully compromised, at least one developer claims to have fallen victim.
Mozilla said it would provide updates if additional details about this campaign become available.
The warning comes after last month’s announcement that Mozilla’s Add-ons Operations team has launched a new security feature to help block malicious Firefox extensions designed to drain cryptocurrency wallets.
Andreas Wagner, the Add-ons Operations Manager who oversees the content security and review efforts for addons.mozilla.org (AMO), stated that Mozilla has identified and removed hundreds of extensions, including fraudulent cryptocurrency wallets, over the past few years.
While not all of these extensions were directly linked to malicious activities, cybercriminals stole $494 million worth of cryptocurrency last year through wallet-draining attacks affecting over 300,000 wallet addresses.

Red Report 2025: Analyzing the Top ATT&CK Techniques Used by 93% of Malware
Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.
Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.
Related Articles:
Hackers target Python devs in phishing attacks using fake PyPI site
SonicWall firewall devices hit in surge of Akira ransomware attacks
Attackers exploit link-wrapping services to steal Microsoft 365 logins
How attackers are still phishing “phishing-resistant” authentication
Threat actors try to downgrade FIDO2 MFA auth in PoisonSeed phishing attack
Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.
Post a Comment Community Rules
You need to login in order to post a comment
Not a member yet? Register Now
You may also like:
null
Popular Stories
- Attackers exploit link-wrapping services to steal Microsoft 365 logins
- Anthropic says OpenAI engineers using Claude Code ahead of GPT-5 launch
- OpenAI prepares new open weight models along with GPT-5
null
Sponsor Posts
- Stop ClickFix Attacks Where They Start: In the Browser
- The State of the Virtual CISO 2025: How AI is Reshaping Cybersecurity and Compliance Services
- View your organization’s attack surface & digital frauds – at no cost. Register now for CTM360’s Community Edition
- Security overwhelm is real. Learn how exposure validation helps you focus on what’s real
- Live webinar: Are your IR playbooks ready for modern identity attacks? Register now.
null
null
Follow us:
Main Sections
- News
- VPN Buyer Guides
- SysAdmin Software Guides
- Downloads
- Virus Removal Guides
- Tutorials
- Startup Database
- Uninstall Database
- Glossary
Community
Useful Resources
Company
- About BleepingComputer
- Contact Us
- Send us a Tip!
- Advertising
- Write for BleepingComputer
- Social & Feeds
- Changelog
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Copyright @ 2003 – 2025 Bleeping Computer® LLC – All Rights Reserved

Leave a comment