LolitideSecurity & privacy

VirusDetector

A Manifest V3 Chrome/Edge extension that detects Silver Fox Trojan phishing and spoofed websites using multi-rule scoring and download blocking.

  • Security
  • Browser extension
  • Browser
  • Runs locally
VirusDetector screenshot
Popularity
306 Stars
GitHub stars
Recent activity
8/24/2026
Maintenance status unclear
License
MIT
Permissive

Why it matters

We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.

Last 90 days

Problem

Addresses the lack of targeted browser-side defense against Silver Fox Trojan and similar phishing attacks through multi-dimensional scoring and download interception.

Practical value

Features a 120-brand domain database and a multi-stage interception mechanism, achieving a strong balance between proactive scanning and reactive download protection.

Innovation / differentiation

Implements BFS-based resource tree traversal and dynamic injection interception to counter download manager bypasses, alongside an RDAP-based domain age decay scoring algorithm.

Leverage potential

Built with pure native JavaScript and zero dependencies, the clear architecture facilitates easy integration into existing browser security stacks.

Why now

Provides immediate and necessary security reinforcement for individual users amidst the rising frequency of phishing sites and malware distribution.

Community activity

In the last 90 days there were 902 new issues and 49 pull requests; the bounded issue/PR samples include 7 issue authors and 10 PR contributors, with 8 releases.

Maintainer responsiveness

The 100-issue window sample had a 98% close rate, and the 49-pull-request sample had a 78% merge rate. Maintainer-response observations covered 100% of that issue sample, with a 4% response rate and median first response of 13.4 hours.

10 contributors in PR sample8 releasesIssue response rate 4% · sample 100 (100% coverage)Median first response 13.4hPR merge rate 78% · 49 sampled in window

Key highlights

  • Multi-dimensional Scoring Engine: Combines domain typosquatting, ICP filing check, RDAP domain age, broken/repeated link analysis, and promotion Emoji density to calculate threat levels
  • Layered Download Interception: Enforces dual-stage security during page load (L0) and download triggers (L3), graying out download buttons and injecting visual warnings when thresholds are met
  • Automated ICP & RDAP Verification: Integrates multi-source ICP regex scanning across Chinese administrative regions and direct RDAP queries to detect high-risk new domains

Quick start

How it is installed, how hard it is, and where to start.

Where it runs

Browser

Difficulty

Easy — follow the steps

Runs locally
  1. 01Download the source code or clone the repository to your local machine: git clone
  2. 02Open Chrome and navigate to chrome://extensions/ (or edge://extensions/ in Microsoft Edge)
  3. 03Enable the "Developer mode" toggle switch in the upper right corner of the extensions page
  4. 04Click "Load unpacked" and select the VirusDetector/ root directory containing manifest.json

Best for

  • Developers who want to try it on their machine

More about it

Virus Detector is an open-source browser extension for Chrome and Edge designed to guard against Silver Fox Trojan phishing and clone websites that masquerade as popular software downloads. Built with zero external dependencies in vanilla JavaScript, it runs on the Manifest V3 Service Worker architecture for light execution.

The extension operates around a multi-rule scoring engine that evaluates visited web pages in real time. It checks domain typosquatting against 120 popular brand signatures, queries domain registration age via RDAP (RFC 9083), scans ICP registration numbers across Chinese provinces, and analyzes page DOM complexity, link consistency, and promotional Emoji density.

Protection is enforced through a layered response mechanism. At the L0 page-load phase, it scans page resources; when cumulative risk scores reach 80, it presents confirmation modals on download actions. At a score of 100, the extension injects page-level blockers that disable download buttons, remove dangerous attributes, and present persistent risk warnings to block malicious payloads.

Sources

Each field shows its status and source — expand to review.

11 · Expand
  • capability tags

    Verified

    security

    Source: admin_cms · cms editor · 8/14/2026

  • Latest release

    Verified

    v2.5.2

    Source: GitHub API · latest_release=v2.5.2 · 10/2/2026

  • License

    Verified

    MIT

    Source: GitHub API · license.spdx_id=MIT · 10/2/2026

  • needs api key

    Verified

    No

    Source: admin_cms · cms editor · 8/14/2026

  • One-liner

    Verified

    {"en":"A Manifest V3 Chrome/Edge extension that detects Silver Fox Trojan phishing and spoofed websites using multi-rule scoring and download blocking.","zh":"基于 Manifest V3 的 Chrome/Edge 扩展,通过多维评分与多层拦截策略实时检测银狐木马钓鱼及仿冒网站。"}

    Source: admin_cms · cms editor · 8/14/2026

  • Platforms

    Verified

    browser

    Source: admin_cms · cms editor · 8/14/2026

  • Category hint

    Inferred from materials

    ai-apps

    Source: Project README · hint=ai-apps · 8/14/2026

  • product forms

    Verified

    browser_extension

    Source: admin_cms · cms editor · 8/14/2026

  • role tags

    Verified

    security

    Source: admin_cms · cms editor · 8/14/2026

  • supports local

    Verified

    Yes

    Source: admin_cms · cms editor · 8/14/2026

  • supports self host

    Verified

    No

    Source: admin_cms · cms editor · 8/14/2026

Other verified projects matched by category, capabilities, and intended roles.