Friday, September 11, 2026

Mozilla Issues Warning on Phishing Campaign Targeting Add-on Developer Accounts

Mozilla has issued an urgent security warning to Firefox add-on developers following the detection of a sophisticated phishing campaign targeting accounts on the Add-ons Mozilla Organization (AMO) platform.

The alert, published by Scott DeVaney from Mozilla’s Add-ons Community team on August 1, 2025, warns developers to exercise extreme caution when receiving emails purporting to be from Mozilla or AMO.

Phishing Campaign Details

The phishing campaign specifically targets developer accounts on addons.mozilla.org, using deceptive emails that claim account updates are required to maintain access to developer features.

According to the Mozilla warning, these fraudulent emails typically contain variations of the message stating “Your Mozilla Add-ons account requires an update to continue accessing developer features”.

The timing of this warning is particularly significant given Mozilla’s growing extension ecosystem.

The Firefox for Android platform alone has expanded from just over 400 extensions at its December launch to more than 1,000 extensions in less than five months, demonstrating the rapid growth and increasing value of the Mozilla add-on developer community.

Mozilla has provided comprehensive guidance to help developers protect their accounts from these phishing attempts.

The company strongly advises developers to avoid clicking any links contained within suspicious emails and to verify that communications originate from legitimate Mozilla-owned domains, including firefox.com, mozilla.org, mozilla.com, or their subdomains.

Technical verification is also crucial for account security. Mozilla recommends that developers ensure emails pass standard authentication checks, including SPF, DKIM, and DMARC verification through their email providers.

Additionally, developers should validate that any links in emails point to official Mozilla domains before accessing them, or preferably navigate directly to these domains rather than following email links.

The warning emphasizes that Mozilla credentials should only be entered on official mozilla.org or firefox.com websites.

This practice helps prevent credential theft, which could compromise not only individual developer accounts but also the extensions they maintain, potentially affecting thousands of Firefox users who rely on these add-ons.

For developers seeking more information about phishing detection and reporting, Mozilla has referenced helpful resources from the U.S. Federal Trade Commission and the U.K. National Cyber Security Centre.

 These organizations provide comprehensive guides on recognizing and avoiding phishing scams, complementing Mozilla’s specific recommendations for add-on developers.

Mozilla has indicated that it will continue monitoring the situation and will update its guidance as new information becomes available.

The company’s proactive approach to warning developers reflects the critical importance of maintaining security within the Firefox extension ecosystem, which serves millions of users worldwide who depend on these tools for enhanced browsing functionality.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News