In the fall of 2026, a new "free open-source anti-detect" appears on GitHub almost every week: a Chromium fork with fingerprint spoofing, a profile manager, a wrapper for Playwright for AI agents. The temptation is clear: a paid anti-detect for 50–100 profiles costs dozens of dollars a month, while this is free. But you give such a program your most valuable assets: proxy logins, cookies from working accounts, and sometimes access to ad accounts and wallets. Below is a step-by-step check that you should complete before the first profile sees your proxies.
Why This Isn't Paranoia: What's Happening on GitHub in 2026
This year, GitHub has become a full-fledged channel for delivering malware. Several documented campaigns show what this looks like in practice:
- Clones of popular projects. The SmartLoader + StealC operation: 109 fake repositories across 103 accounts. Malicious actors copied the structure and README of real projects, replacing the source code with a "download ZIP" button containing a downloader and info stealer. The campaign lasted more than seven weeks.
- Speed of response. Fake DeepSeek TUI repositories appeared within four hours of the official announcement of the tool. Anything trending is cloned almost instantly.
- Hidden code. The GlassWorm campaign (433+ infected components on GitHub, npm, VS Code Marketplace, and OpenVSX) hid malicious logic in invisible Unicode characters that are not visible during a normal diff view.
- Proxy bot included. In the fake "leak" of Claude Code and the fakes of DeepSeek TUI, along with the Vidar stealer, GhostSocks was installed — malware that turns the victim's computer into a SOCKS5 proxy.
The last point is particularly unpleasant for our audience. According to Infrawatch, GhostSocks spreads in conjunction with the LummaC2 stealer and is sold as a service: it wraps a tunnel in TLS and gives the renter a "clean" home IP of the infected machine. This means that a "free" anti-detect can not only steal your accounts but also turn your own IP into an outgoing node of someone else's botnet. In a couple of weeks, you may wonder why your home address ended up in spam databases.
How Open-Source Anti-Detects Differ from Each Other
Before checking a specific build, it's useful to understand what type it belongs to — this will determine what exactly to look for.
- Engine-level patches. An example is Camoufox: a Firefox build where the fingerprint (navigator, screen, WebGL, fonts, time zone, WebRTC) is spoofed in C++ code, not through JS injection. The official repository is
daijro/camoufox, and the package on PyPI is calledcamoufox. An important detail: according to the project itself, the source code became fully open only starting from version v146; versions v135.0.1-beta.24 and below contained closed components. In 2026, the project had a long hiatus in support, and Centinel analysts detected it in the September benchmark of Camoufox. - Wrappers over regular Chrome. undetected-chromedriver, UC mode in SeleniumBase. They are transparent by themselves, but they work worse against Cloudflare, DataDome, and Kasada: they mainly modify the JavaScript layer.
- New Chromium forks with ready binaries. The riskiest group: a project with several dozen stars that offers to download a built
.exeor.dmgfile over 200+ MB. An ordinary user cannot verify that the binary is built from the published code.
Step-by-Step Check Before Installation
Step 1. Ensure It's the Original, Not a Clone
- Find the project from the official website or documentation, not from a GitHub search. Clones often have the same name and a copied README.
- Compare the repository creation date, number of commits, and authors. A clone is usually created recently, has 1–3 commits ("Initial commit," "Update README"), and stars are inflated within a few days.
- Look at Issues and Discussions. A live project has bug reports from different people and responses from the maintainer. Closed Issues in a "popular" project are a red flag.
- Forks like
random-nick/camoufoxare not equal to the original, even if the description states "official."
Step 2. Check Where the Binary Comes From
- The download link should lead to the Releases tab of the same repository, not to a file-sharing site, Google Drive, or a "mirror" in the README. The "Download ZIP" button in the description is the same trick from the SmartLoader campaign.
- Check if the release is built through GitHub Actions from public code. Is there a build workflow, do the tags match? If the project publishes build attestations, verify them with the command
gh attestation verify. - Compare the file's checksum (SHA-256) with the one specified in the release. If checksums are not provided, that's a reason to be cautious, not to skip this step.
- Upload the file to VirusTotal. Zero detections guarantee nothing: fresh stealers are often clean in the first days. However, detections with labels like stealer, Lumma, Vidar, or proxy are a reason to stop immediately.
Step 3. Read the Code Where Surprises Are Hidden
You don't need to read all of Chromium. It's enough to check the points through which the program accesses the network and executes something:
- installation and post-installation scripts (
postinstallinpackage.json,setup.py,install.sh, PowerShell scripts); - the "updates" and "telemetry" module: where requests go and what is transmitted;
- any calls to external URLs, base64 strings, loading code from a remote address and executing it;
- invisible characters: run the source code through a search for non-ASCII characters. This is how GlassWorm hid.
If the project is a "launcher" that downloads the engine from its own server on the first run, the launcher source code says almost nothing about what will end up on your disk.
Step 4. First Launch — Only in a Sandbox
- Run the program in a separate virtual machine or on a clean VPS without your work data.
- Do not connect working proxies and accounts. For the first run, a test proxy with a small amount of traffic will suffice.
- Check the network connections of the process (Little Snitch, Wireshark,
netstat/ss). The anti-detect needs connections to the sites you open and to your proxy. Persistent connections to unknown IPs and ports, especially incoming or "hanging" TLS sessions to one address, are signs of a backdoor or proxy bot. - Check the autostart and task scheduler after installation: are there any new services, cron jobs, or LaunchAgents that you didn't install.
Step 5. Check That the Fingerprint Doesn't Give You Away
An honest but poor anti-detect is also dangerous — just in a different way: accounts get banned due to inconsistencies. Run the profile through several checkers and be sure to check for network leaks. We discussed the detailed order in the article "WebRTC and DNS Leaks: 7 Checks Before Logging into a Profile". The minimum for any new build:
- WebRTC does not reveal the local and real external IP, only the proxy IP;
- DNS requests go through the proxy, not through the provider;
- the time zone, language, and geolocation match the country of the proxy;
- User-Agent and Client Hints correspond to the actual version of the engine (a fork on Chromium 151 that presents itself as Chrome 153 is caught immediately).
Pitfalls That Are Often Forgotten
- License. "Open code" does not always mean "can be used for business." For example, Damru has a PolyForm Noncommercial license: commercial use is not permitted.
- Abandoned projects. An anti-detect without updates becomes outdated in months: the base version of the browser lags behind, and detectors learn from its artifacts. The history of Camoufox shows that even a strong project can fall out of the race for a year.
- Profile synchronization "in the cloud." If a free build offers cloud storage for profiles, your cookies and passwords for proxies are stored on someone else's server. Find out whose exactly.
- Proxy keys and passwords in plain text. Many homemade managers store proxy logins in unencrypted JSON next to the profile. The stealer will grab them first.
- Hacked paid anti-detects. "Cracked" Multilogin, Dolphin, and similar tools are classic bait for stealers. This is worse than any open-source: there is no code at all, and the distributor knows in advance that the victim is working with accounts.
What Proxies to Use with a New Anti-Detect
Separate testing and work. During the testing phase, use a separate proxy with minimal remaining traffic: if the build turns out to be malicious, you will lose a few cents, not your working pool. For operational profiles, you need proxies that won't spoil the fingerprint: residential proxies provide IPs from home providers and are suitable for most multi-accounting scenarios, while for social networks and ad accounts with strict anti-fraud measures, mobile proxies with addresses from telecom operators work better.
A separate rule: for each new tool — its own sub-account or proxy login. If the program turns out to have a "surprise," you will change one password and won't have to remember where else you entered the shared one. The same principle of isolating secrets saved teams from campaigns like Flooding Dropper in npm, which specifically targeted the credentials of proxy scraping teams.
Short Checklist
- Found the project through the official website, not through search; it's not a clone or random fork.
- The binary is in Releases, built in CI, and the checksum matches.
- Checked installation, update, and telemetry scripts, searched for invisible characters.
- First launch — in a virtual machine, with a test proxy, under network and autostart monitoring.
- The fingerprint passed WebRTC, DNS, time zone, and Client Hints checks.
- The license allows my use, and the project has been updated in recent months.
- For the new tool — separate proxy logins.
Conclusion
A free anti-detect from GitHub can be an excellent tool, but only after verification. In 2026, attackers clone trending repositories within hours, hide code in invisible characters, and include proxy bots with stealers that turn your computer into someone else's outgoing node. Half an hour spent checking against the checklist is worth less than one stolen set of cookies from an ad account. And a separate test proxy with a small amount of remaining traffic makes such a check almost free.
