LolitideSecurity & privacy
VirusDetector
A Manifest V3 Chrome/Edge extension that detects Silver Fox Trojan phishing and spoofed websites using multi-rule scoring and download blocking.
- Security
- Browser extension
- Browser
- Runs locally

- Popularity
- 306 Stars
- GitHub stars
- Recent activity
- 8/24/2026
- Maintenance status unclear
- License
- MIT
- Permissive
Why it matters
We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.
Problem
Addresses the lack of targeted browser-side defense against Silver Fox Trojan and similar phishing attacks through multi-dimensional scoring and download interception.
Practical value
Features a 120-brand domain database and a multi-stage interception mechanism, achieving a strong balance between proactive scanning and reactive download protection.
Innovation / differentiation
Implements BFS-based resource tree traversal and dynamic injection interception to counter download manager bypasses, alongside an RDAP-based domain age decay scoring algorithm.
Leverage potential
Built with pure native JavaScript and zero dependencies, the clear architecture facilitates easy integration into existing browser security stacks.
Why now
Provides immediate and necessary security reinforcement for individual users amidst the rising frequency of phishing sites and malware distribution.
Community activity
In the last 90 days there were 902 new issues and 49 pull requests; the bounded issue/PR samples include 7 issue authors and 10 PR contributors, with 8 releases.
Maintainer responsiveness
The 100-issue window sample had a 98% close rate, and the 49-pull-request sample had a 78% merge rate. Maintainer-response observations covered 100% of that issue sample, with a 4% response rate and median first response of 13.4 hours.
Key highlights
- Multi-dimensional Scoring Engine: Combines domain typosquatting, ICP filing check, RDAP domain age, broken/repeated link analysis, and promotion Emoji density to calculate threat levels
- Layered Download Interception: Enforces dual-stage security during page load (L0) and download triggers (L3), graying out download buttons and injecting visual warnings when thresholds are met
- Automated ICP & RDAP Verification: Integrates multi-source ICP regex scanning across Chinese administrative regions and direct RDAP queries to detect high-risk new domains
Quick start
How it is installed, how hard it is, and where to start.
Where it runs
Browser
Difficulty
Easy — follow the steps
- 01Download the source code or clone the repository to your local machine: git clone
- 02Open Chrome and navigate to chrome://extensions/ (or edge://extensions/ in Microsoft Edge)
- 03Enable the "Developer mode" toggle switch in the upper right corner of the extensions page
- 04Click "Load unpacked" and select the VirusDetector/ root directory containing manifest.json
Best for
- Developers who want to try it on their machine
More about it
Virus Detector is an open-source browser extension for Chrome and Edge designed to guard against Silver Fox Trojan phishing and clone websites that masquerade as popular software downloads. Built with zero external dependencies in vanilla JavaScript, it runs on the Manifest V3 Service Worker architecture for light execution.
The extension operates around a multi-rule scoring engine that evaluates visited web pages in real time. It checks domain typosquatting against 120 popular brand signatures, queries domain registration age via RDAP (RFC 9083), scans ICP registration numbers across Chinese provinces, and analyzes page DOM complexity, link consistency, and promotional Emoji density.
Protection is enforced through a layered response mechanism. At the L0 page-load phase, it scans page resources; when cumulative risk scores reach 80, it presents confirmation modals on download actions. At a score of 100, the extension injects page-level blockers that disable download buttons, remove dangerous attributes, and present persistent risk warnings to block malicious payloads.
Sources
Each field shows its status and source — expand to review.
11 · Expand
Sources
Each field shows its status and source — expand to review.
capability tags
Verifiedsecurity
Source: admin_cms · cms editor · 8/14/2026
Latest release
Verifiedv2.5.2
Source: GitHub API · latest_release=v2.5.2 · 10/2/2026
License
VerifiedMIT
Source: GitHub API · license.spdx_id=MIT · 10/2/2026
needs api key
VerifiedNo
Source: admin_cms · cms editor · 8/14/2026
One-liner
Verified{"en":"A Manifest V3 Chrome/Edge extension that detects Silver Fox Trojan phishing and spoofed websites using multi-rule scoring and download blocking.","zh":"基于 Manifest V3 的 Chrome/Edge 扩展,通过多维评分与多层拦截策略实时检测银狐木马钓鱼及仿冒网站。"}
Source: admin_cms · cms editor · 8/14/2026
Platforms
Verifiedbrowser
Source: admin_cms · cms editor · 8/14/2026
Category hint
Inferred from materialsai-apps
Source: Project README · hint=ai-apps · 8/14/2026
product forms
Verifiedbrowser_extension
Source: admin_cms · cms editor · 8/14/2026
role tags
Verifiedsecurity
Source: admin_cms · cms editor · 8/14/2026
supports local
VerifiedYes
Source: admin_cms · cms editor · 8/14/2026
supports self host
VerifiedNo
Source: admin_cms · cms editor · 8/14/2026
Related projects
Other verified projects matched by category, capabilities, and intended roles.
vault
An open-source security platform for centralized management, encryption, and auditing of sensitive credentials like API keys, passwords, and certificates.
openbao
An open-source secrets management system for storing, distributing, rotating, and controlling access to secrets, certificates, and keys.
fleet
A device-management platform for IT and security teams covering MDM, software deployment, patching, inventory queries, and compliance across desktop and mobile operating systems.
agent-governance-toolkit
A governance toolkit for AI agents that adds policy checks, identity, audit trails, sandboxing, and SRE controls across multiple agent frameworks.
syzkaller
An unsupervised, coverage-guided kernel fuzzer that supports multiple operating systems.
cli
Command-line tool to scan and monitor software projects for security vulnerabilities.
