metamask-update.github.io
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of metamask-update.github.io
This domain appears to host a website themed around MetaMask, a well-known cryptocurrency wallet and Web3 access platform. The page title and meta description present it as a place to buy, sell, swap, and manage digital assets, and the screenshot shows MetaMask branding, wallet-style imagery, and a prominent call to action to “Get MetaMask.” Based on the visible content, the site is positioned as a cryptocurrency-related landing page rather than a general informational blog or unrelated personal page.
However, the domain itself is not the primary MetaMask domain shown in the page metadata. Instead, it uses a GitHub Pages subdomain that closely resembles the official brand name while adding an extra word. That pattern may indicate an unofficial promotional page, a fan-made clone, or a look-alike site attempting to benefit from user familiarity with the MetaMask brand. Based on available data, it appears to be hosted through GitHub Pages rather than on infrastructure clearly associated with the official MetaMask website.
Safety Assessment for metamask-update.github.io
Several security signals raise concern at the time of this scan. The domain was flagged by 8 out of 89 security engines, with multiple detections classifying it as phishing. In addition, the domain closely resembles metamask.io and may be a look-alike intended to imitate the legitimate MetaMask brand. The page metadata explicitly references “Metamask.io,” and the screenshot shows MetaMask branding and a “Get MetaMask” prompt, which strengthens the possibility that visitors could mistake it for an official site.
Other scan results were less severe: the malware scan did not identify flagged files, and major content-malice and phishing blocklists included in the scan were reported clean at the time of review. Even so, clean file-scan results do not rule out credential theft or wallet-targeting phishing, especially when the main concern is brand imitation rather than malware delivery. The lack of a traffic ranking and the use of a GitHub Pages subdomain also add context that may be relevant when assessing legitimacy.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid Let's Encrypt certificate that was valid until 2026-10-31 at the time of this scan. It resolves to IP address 185.199.109.153 and appears to be hosted on GitHub Pages infrastructure in the United States. The web server was identified as GitHub.com, which is consistent with a static site deployment rather than a dedicated standalone hosting environment.
DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from that additional integrity layer. No malicious files, flagged external links, or iframe-based issues were reported by the malware scan, but the primary technical concern is not server-side malware; it is the apparent use of a brand-resembling GitHub Pages domain that may be used for phishing or impersonation.
Share your experience with this website. Was it safe? Did you encounter any issues?