Ross ROSS = Recommend OSS · open-source software intelligence for agents

noob-hackers/mrphish

All In One Social Accounts Phishing With Otp Bypass In Termux. observed · 2026-08-28

github.com/noob-hackers/mrphish · homepage · Shell · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

50/100

  • Activity 39
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2191
  • days_rel: n/a
  • days_push: 371
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2320 stars · 175 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

mrphish is a Bash-based Termux script that hosts fake social media login pages (60+ templates) with port forwarding via ngrok and OTP bypass features, aimed at phishing social media accounts. It runs on rooted and non-rooted Android devices and requires PHP and an ngrok token.

Use cases

  • run phishing page simulations for social media accounts in termux
  • set up a fake login page with ngrok port forwarding on android
  • test otp bypass techniques during a security assessment
  • demonstrate social engineering risks with cloned instagram login pages
  • host credential-capture pages from a non-rooted android phone

When to choose

  • you need a quick, menu-driven phishing simulation toolkit that runs entirely in termux on android
  • you want many prebuilt social media login page templates without writing your own
  • you are doing an authorized social-engineering demo and want ngrok tunneling built in

When to avoid

  • you need a compliant, enterprise-grade phishing simulation platform with reporting and training features
  • you want a tool that works outside termux or on desktop linux without modification
  • your use of phishing pages is not explicitly authorized - using this against real accounts is illegal

Facets

cli-tool · maturity maintenance

security cli http-server security penetration-testing cli phishing social-engineering termux-tools otp-bypass port-forwarding ngrok bash-script security-testing command-line android termux

4 sources

Member repositories

RepositoryRoleHealth v2
noob-hackers/mrphishmain50

For agents

markdown · JSON · MCP: product_card(name="noob-hackers/mrphish")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem