Malware will have an unlimited number of methods to continue patching Firefox, this change only makes it harder for regular users to configure Firefox manually for installing extensions that have not been blessed by Mozilla.
I feel like the people we consider ”regular users” to be really different.
Like we’re talking about a subset of the population that want’s to install their own private extensions or sideload someone else’s but doesn’t understand how to uninstall the release version and install the developer edition when prompoted.
It's also possible to make this setting configurable only from the browser UI, where you get a chance to educate and properly warn your users.
They also want to restrict the config option on Linux, where the adware problem you describe is not really present.