# noob-hackers/mrphish

All In One Social Accounts Phishing With Otp Bypass In Termux.

Repository: https://github.com/noob-hackers/mrphish
Canonical: https://ross.abutalabs.com/products/mrphish
Homepage: https://www.noob-hackers.com
Language: Shell
License: MIT
License Family: permissive
Topics: termux, instagram, instagramclone, bash, termuxtools, noob, noobhackers, noobhackersyt, termux-tools, termux-hacking
Last push: 2025-08-27T12:49:30+00:00

## Health v2 (maintenance only)
Score: 50/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 39, release rhythm 35, longevity 100
- inputs: {"age_days": 2191, "days_push": 371, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2320, forks 175 (observed 2026-08-28T04:06:37.090274+00:00)

## What it is
mrphish is a Bash-based Termux script that hosts fake social media login pages (60+ templates) with port forwarding via ngrok and OTP bypass features, aimed at phishing social media accounts. It runs on rooted and non-rooted Android devices and requires PHP and an ngrok token.

## Use cases
- run phishing page simulations for social media accounts in termux
- set up a fake login page with ngrok port forwarding on android
- test otp bypass techniques during a security assessment
- demonstrate social engineering risks with cloned instagram login pages
- host credential-capture pages from a non-rooted android phone

## When to choose
- you need a quick, menu-driven phishing simulation toolkit that runs entirely in termux on android
- you want many prebuilt social media login page templates without writing your own
- you are doing an authorized social-engineering demo and want ngrok tunneling built in

## When to avoid
- you need a compliant, enterprise-grade phishing simulation platform with reporting and training features
- you want a tool that works outside termux or on desktop linux without modification
- your use of phishing pages is not explicitly authorized - using this against real accounts is illegal

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, cli, http-server
- domain: security, penetration-testing
- platform: cli
- tags: phishing, social-engineering, termux-tools, otp-bypass, port-forwarding, ngrok, bash-script, security-testing, command-line, android, termux

## Member repositories
- noob-hackers/mrphish (main) score 50

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:37.090274+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:38:49.876998+00:00, confidence not recorded.
  - readme: https://github.com/noob-hackers/mrphish (fetched 2026-08-28T04:06:37.090274+00:00, sha 340894527bbc)
  - homepage: https://www.noob-hackers.com (fetched 2026-08-29T10:19:00.172771+00:00, sha 942c97cdba5a)
  - site_page: https://www.noob-hackers.com/2025/03/how-to-install-windows-10-in-termux.html (fetched 2026-08-29T10:19:00.184199+00:00, sha ea5e44a7492e)
  - site_page: https://www.noob-hackers.com/2025/03/how-to-install-ubuntu-in-termux.html (fetched 2026-08-29T10:19:00.186540+00:00, sha adba327c7491)
- Data as of 2026-08-30T08:39:29.467469+00:00.
