Yodel Phish
Overview
Open-source protection against Phishing / ClickFix / Device Code Auth phishing
An open-source browser extension that uses computer vision to detect potentially malicious login pages, blocks ClickFix attacks, and stops malicious OAuth device-code sign-ins. Everything runs locally in the browser, no data or screenshots are sent to a backend. ## How to use the extension 1. Setup: add websites to your Trusted Sites list After installation, visit the login pages of services you use, such as email or online banking. Yodel Phish detects login pages and lets you add the site to your Trusted Sites list and select the company’s logo. The hostname, logo, and relevant brand terms are stored locally (no full-page screenshot is saved). 2. Be protected: while browsing, Yodel Phish detects login pages and automatically runs the detection pipeline When the detection pipeline is run, domain name, visual and textual information are extracted and analyzed against data from your Trusted Sites list. If a risk is detected, Yodel Phish will raise a warning or block a login attempt. Get clear results The analysis results are displayed in easy to understand banners: - Blue: informational - Green: safe/trusted site - Orange: potential risk detected - Red: phishing, blocking warning The user can set the preferred font size for the text displayed in the banners in the settings. ## How does it work Yodel Phish combines signals such as domain names, OCR-detected brand text, computer-vision logo matching, and image embeddings into a detection score. ### Phishing The extension detects phishing pages that imitate trusted login sites on the wrong domain. If a page looks like a saved trusted service but is hosted somewhere else, the extension blocks the page and warns you before you enter your credentials. ### ClickFix The extension detects when a website tries to copy a PowerShell, Terminal, Command Prompt, Run dialog, or other system command to your clipboard. It blocks the command by default and shows you exactly what was blocked, including hidden control characters. Yodel Phish detects automatic clipboard copying, Ctrl+C, and right-click copying. Two modes are available: strict (for non-technical users) and warning (for power users) ### Device-code sign-ins The extension detects dangerous OAuth device-code sign-in attempts. If an unrelated website sends you to a device-code page, the extension interrupts the navigation and warns you. Two modes are available: strict (for non-technical users) and warning (for power users) ## Features overview - Local page analysis: Uses Tesseract OCR, OpenCV, YOLO, and DINOv2 in the extension to assess login-page impersonation. - Trusted-site references: Lets you save legitimate sites, with logo and brand evidence used for future comparisons. - Hard phishing warnings: Interrupts high-confidence login impersonation with an explicit warning page. - ClickFix protection: Warns or blocks dangerous clipboard writes from webpages in the default strict mode. - Device-code protection: Warns or blocks risky OAuth device-code navigation, depending on its origin and policy. - Trusted and muted sites: Lets you manage exact hostnames that are trusted or muted; ClickFix and device-code protection remain active on muted sites. - Manual analysis: Provides a one-click analysis action from the extension popup. - Accessible warnings: Uses clear severity labels, visible controls, and configurable banner text size. - Advanced diagnostics: Optional, local analysis history can be reviewed, exported as JSON, or cleared. For more information and screen recordings: https://w0-0p.github.io/yodel-phish/
0 out of 5No ratings
Details
- Version0.1.1
- UpdatedAugust 31, 2026
- Offered byyodel.phish
- Size124MiB
- LanguagesEnglish
- Developer
Email
yodel.phish@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site