InspirationEvery day, millions of Indians receive scam messages — fake bank alerts, "digital arrest" threats from fake CBI officers, KBC lottery frauds, and UPI collect requests that steal money instead of sending it. The elderly and first-time smartphone users are the most vulnerable. Existing tools are English-only or just block numbers without explaining anything. I built ScamShield so anyone can instantly check if a message, link, or screenshot is a scam — in Hindi or English.What it does- Message analyzer: paste any SMS/WhatsApp text → instant Safe / Suspicious / Dangerous verdict with a 0–100 risk score, red flags, and action advice- URL checker: detects phishing links, fake bank domains, URL shorteners, and homoglyph attacks- Screenshot OCR: upload a scam screenshot → text extracted in seconds (server-side) → auto-analyzed- Scam library: India's 6 most common fraud scripts with spotting tips- Response guide: step-by-step what to do if scammed, with cybercrime.gov.in and helpline 1930- Hindi + English full UI, voice verdict readout, history, PWA, and a browser extension (select text → right-click → analyze)How I built itFrontend: React + TypeScript + Vite + Tailwind (dark + gold mobile-first UI, PWA with offline scam library). Backend: Node.js + Express with a transparent 4-stage pipeline — Extractor → Scorer → Explainer → Advisor. Detection combines 20+ hand-tuned scam pattern detectors, TF-IDF/cosine similarity against known fraud templates, homoglyph normalization, and combo bonuses. OCR runs server-side with a warm Tesseract worker (~2s per image). Deployed on Render, extension is Manifest V3.Challenges I ran into- Browser-side OCR kept timing out: the PWA service worker was intercepting Tesseract's blob: workers. Fixed by bypassing non-HTTP requests in the SW, then moved OCR server-side entirely for speed and reliability.- Short scam messages ("Pay 50000") slipped through — tuned money-request patterns and weights across 9 adversarial test rounds (18 bugs fixed, 43/43 E2E tests passing).- Keeping it honest: it's a rule-based engine, so I label it as such — no fake "AI" claims.Accomplishments that I'm proud ofA fully working product with zero dead buttons: 17/17 browser tests pass on desktop + mobile, Hindi support as a real differentiator, and screenshot-to-verdict in under 10 seconds.What I learnedAdversarial testing beats happy-path testing — every "judge round" found real misses. Also: service workers and Web Workers don't mix without care, and honest labeling builds more trust than hype.What's next for ScamShieldCommunity-reported scam numbers, SMS auto-read on Android (with permission), and more Indian language support.
Built With
- express.js
- node.js
- pwa
- react
- render
- tailwind-css
- tesseract.js
- typescript
- vite
Log in or sign up for Devpost to join the conversation.