Mozilla warns of phishing attacks targeting add-on developers

https://www.bleepingcomputer.com/news/security/mozilla-warns-of-phishing-attacks-targeting-add-on-developers/?&web_view=true

Nudge
  • Home
  • News
  • Security
  • Mozilla warns of phishing attacks targeting add-on developers

Mozilla warns of phishing attacks targeting add-on developers

By

Sergiu Gatlan
  • August 4, 2025
  • 06:00 AM
  • 0
Mozilla

Mozilla has warned browser extension developers of an active phishing campaign targeting accounts on its official AMO (addons.mozilla.org) repository.

Mozilla’s add-on platform hosts over 60,000 browser extensions and more than 500,000 themes used by tens of millions of users worldwide.

According to Mozilla’s advisory, these phishing emails are impersonating the AMO team and claim that the targeted developer accounts require updates to maintain access to development features.

“The developer community should be aware we’ve detected a phishing campaign targeting AMO (addons.mozilla.org) accounts. Add-on developers should exercise extreme caution and scrutiny when receiving emails claiming to be from Mozilla/AMO,” Mozilla cautioned on Friday.

“Phishing emails typically state some variation of the message’ Your Mozilla Add-ons account requires an update to continue accessing developer features.’”

ADVERTISEMENT

SCROLL TO CONTINUE READING

To secure their accounts, developers are advised to always verify if emails they receive are sent from a Mozilla domain (firefox.com, mozilla.org, mozilla.com, or their subdomains), that they pass standard email authentication checks (including SPF, DKIM, and DMARC), and not to click on links embedded in suspicious emails.

Mozilla also urged developers to navigate directly to its websites rather than following email links, and only enter their login credentials on official Mozilla or Firefox domains.

Mozilla phishing email

Mozilla phishing email (Juraj)

​While Mozilla has yet to disclose the scale of this phishing campaign, the end goal of the attacks, or whether any developer accounts had already been successfully compromised, at least one developer claims to have fallen victim.

Mozilla said it would provide updates if additional details about this campaign become available.

The warning comes after last month’s announcement that Mozilla’s Add-ons Operations team has launched a new security feature to help block malicious Firefox extensions designed to drain cryptocurrency wallets.

Andreas Wagner, the Add-ons Operations Manager who oversees the content security and review efforts for addons.mozilla.org (AMO), stated that Mozilla has identified and removed hundreds of extensions, including fraudulent cryptocurrency wallets, over the past few years.

While not all of these extensions were directly linked to malicious activities, cybercriminals stole $494 million worth of cryptocurrency last year through wallet-draining attacks affecting over 300,000 wallet addresses.

Picus Red Report 2025

Red Report 2025: Analyzing the Top ATT&CK Techniques Used by 93% of Malware

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

Related Articles:

Hackers target Python devs in phishing attacks using fake PyPI site

SonicWall firewall devices hit in surge of Akira ransomware attacks

Attackers exploit link-wrapping services to steal Microsoft 365 logins

How attackers are still phishing “phishing-resistant” authentication

Threat actors try to downgrade FIDO2 MFA auth in PoisonSeed phishing attack

Sergiu Gatlan

Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Post a Comment Community Rules
You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-0920899300397823&output=html&h=344&slotname=4359266829&adk=3161097733&adf=1433740278&pi=t.ma~as.4359266829&w=492&abgtt=1&cr_col=4&cr_row=2&fwrn=2&lmt=1754301615&rafmt=9&format=492×344&url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fmozilla-warns-of-phishing-attacks-targeting-add-on-developers%2F%3F%26web_view%3Dtrue&crui=image_stacked&fwr=0&wgl=1&dt=1754404023178&bpp=2&bdt=1371&idt=863&shv=r20250731&mjsv=m202507280101&ptt=9&saldr=aa&abxe=1&cookie_enabled=1&eoidce=1&correlator=1472464878249&frm=20&pv=2&u_tz=-240&u_his=1&u_h=1119&u_w=522&u_ah=1119&u_aw=522&u_cd=24&u_sd=2.069&adx=15&ady=4483&biw=522&bih=955&scr_x=0&scr_y=0&eid=95360549%2C95362655%2C95368265%2C95359265%2C95367171&oid=2&pvsid=4743135196184229&tmod=180435989&uas=0&nvt=1&fc=896&brdim=0%2C32%2C0%2C32%2C522%2C0%2C514%2C1011%2C522%2C955&vis=1&rsz=%7C%7CpeEbr%7C&abl=CS&pfx=0&fu=128&bc=31&bz=0.98&ifi=1&uci=a!1&btvi=1&fsb=1&dtd=890

null

Popular Stories

null

Sponsor Posts

null

null

Follow us:
Main Sections
Community
Useful Resources
Company

Terms of UsePrivacy PolicyEthics StatementAffiliate Disclosure

Copyright @ 2003 – 2025 Bleeping Computer® LLC – All Rights Reserved

Leave a comment

Design a site like this with WordPress.com
Get started