Windows 10 reached EOS (end of support) on October 14, 2025. If you are on Windows 10, see this article.

Поиск в поддержке

Избегайте мошенников, выдающих себя за службу поддержки. Мы никогда не попросим вас позвонить, отправить текстовое сообщение или поделиться личной информацией. Сообщайте о подозрительной активности, используя функцию «Пожаловаться».

Подробнее

How do I escalate the presence of a malicious extension for removal from the store?

  • 3 ответа
  • 0 имеют эту проблему
  • 97 просмотров
  • Последний ответ от RealDeer

[Coupongogo: Automatic Coupons & Cashback](https://addons.mozilla.org/en-US/firefox/addon/coupongogo-automatic-coupons/) is a malicious extension programed with a command and control server located in China.

Despite [Firefox user reports](https://www.reddit.com/r/firefox/comments/1pl0u6m/malicious_addon_does_not_get_taken_down/), the extension remains available on the Mozilla addon store.

A [rastersec.com contributor explains](https://www.rastersec.com/blog/coupongogo-cryptostealer),

>\[Coupongogo\] operates as a remote-controlled time bomb, utilizing a dynamic configuration system to evade detection, hijack all search and browsing traffic, and wait for a server command to activate its dormant theft capabilities targeting major cryptocurrency exchanges.

Given the lack of success at securing the privacy and security of users by using the standard addon reporting tool, how can I escalate this matter to a responsible Mozilla party for triage?

[Coupongogo: Automatic Coupons & Cashback](https://addons.mozilla.org/en-US/firefox/addon/coupongogo-automatic-coupons/) is a malicious extension programed with a command and control server located in China. Despite [Firefox user reports](https://www.reddit.com/r/firefox/comments/1pl0u6m/malicious_addon_does_not_get_taken_down/), the extension remains available on the Mozilla addon store. A [rastersec.com contributor explains](https://www.rastersec.com/blog/coupongogo-cryptostealer), >\[Coupongogo\] operates as a remote-controlled time bomb, utilizing a dynamic configuration system to evade detection, hijack all search and browsing traffic, and wait for a server command to activate its dormant theft capabilities targeting major cryptocurrency exchanges. Given the lack of success at securing the privacy and security of users by using the standard addon reporting tool, how can I escalate this matter to a responsible Mozilla party for triage?

Выбранное решение

Все ответы (3)

Выбранное решение

Discussion of things related to addons.mozilla.org is done at https://discourse.mozilla.org/c/add-ons/35

Thank you both for the helpful information.

The Mozilla team has acted on the reports.

Задать вопрос

Для ответа на сообщения вы должны войти в свою учётную запись. Пожалуйста, задайте новый вопрос, если у вас ещё нет учётной записи.