People should always be educated if the add ons are legit by checking on the home page of the official website and if it's not available on the website take your time to send a ticket to double-check if the add ons is the official ones, there are fake reviews on add ons just like they do on Playstore and Google map, I have seen developers hiring and paying people to give fake reviews.
There is a lot of material educating people on how to be security conscious and keeping safe from the malicious apps and website but some people continue to be careless anyway
I also found the same thing about Safepal add-ons on google chrome and it seems the scammers not only put it in the Mozilla browser but also in Chrome.
We should report the apps so that they get taken down. It's surprising that the app was published almost a year ago, and the trick they used was to present it as a theme. I have reported it.