I've developed a few browser extensions, and every week I receive numerous emails with "revenue offer". Some experienced developers know that offers like these will inject malware into the browsers of your users, but scammers who make these offers will not tell you about it. They offer "integrations" that don't look so suspicious. Imagine how many developers have accepted these offers. Then look at the number of extensions in your browser and think about how much risk there is that you have an extension with malware.
You can see the code of extensions, but it may be minimized, so it hard to known what the code do.
Extensions with label “Recommended” are pass the manual review of Firefox moderators, so you can trust them more than addons with no this label. However you still should keep in mind that any extension developer may be victim of complex scam attack.
The most probable reason usually is a not enough funding the developers
Developer spend time on maintaining the project but users does not donate them
Scammers offer to developer some integrations that not looks too suspicious and allow them to earn some money
Developer agree offer and after some time scammers enables malware to hack extension users
To minimize the possibility of hijacking addons by scammers, we have to:
conduct background check before install extension
ensure the extension have github with open source code and developer are real person
ensure development are active and developer have high engineering skill, check them respond on feedback and issues
donate the developer if you like the product, to motivate them keep distance of scammers offers
You can see the code of extensions, but it may be minimized, so it hard to known what the code do.
Extensions with label “Recommended” are pass the manual review of Firefox moderators, so you can trust them more than addons with no this label. However you still should keep in mind that any extension developer may be victim of complex scam attack.
The most probable reason usually is a not enough funding the developers
To minimize the possibility of hijacking addons by scammers, we have to: