Blocks ClickFix / pastejacking — pages that trick you into copying a malicious command and pasting it into a terminal. Cross-platform, instant, local.
rmthreat builds small, on-device browser extensions that each watch a different doorway — your clipboard, your code, your logins — and stay out of your way until something's wrong.
Each is free, open source, and runs entirely on your device. Pick the doorway you want watched.
Blocks ClickFix / pastejacking — pages that trick you into copying a malicious command and pasting it into a terminal. Cross-platform, instant, local.
Read-only alerts for fake-interview malicious-repo traits as you open files on GitHub, GitLab or Bitbucket. It only warns — never blocks, modifies or uploads.
On-device, explainable detection of credential-harvesting UI — fake login windows, browser-in-the-browser spoofs, cross-origin forms and seed-phrase prompts.
Detection runs in your browser and works offline.
No IP, cookies, or personal data. Telemetry is opt-in or none.
Every alert says what it saw and why, in plain words.
Auditable code on GitHub — no hidden behavior.