DKDKCISSPSearch
Threat Research

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.

DKCISSP News DeskThe Hacker News25 Sept 2026, 10:04 am
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.

Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure." As of writing, the domain has been marked as malicious and unsafe on both VirusTotal and Google's Safe Browsing list .

The tell only appears at request time, from the caller that matters." The disclosure comes as Manifold said it has since identified 13 more placeholder domains that are not IANA-reserved, with two of them – yoursite[.]com and your-domain[.]com – serving scams and scareware to macOS visitors and an ordinary parking page to other users.

ClickFix is a social engineering attack technique in which either malicious or legitimate-but-compromised websites display error messages, browser alerts, or CAPTCHA verification prompts, tricking users into copying and executing hidden commands via the Windows Run dialog or Terminal to "fix" the issue.

Please try again from a Windows device." A search on GitHub shows that the domain is referenced in over 1,700 public repositories, including those related to AI agent skills and MCP-server docs that cite "third-party[.]com" as an example endpoint.

To counter the threat, it's advised to audit their documentation and treat non-reserved placeholder domains (e.g., yourcompany[.]com, mycompany[.]com, your-api[.]com, and their lookalikes) as squattable and open to abuse by threat actors, who can register them and serve malicious content.

Often, web pages using ClickFix rely on clipboard hijacking to automatically inject malicious script or commands into the victim's clipboard for subsequent pasting on Windows Run dialog or macOS Terminal.

Windows users visiting the page are shown a Cloudflare check that poisons the victim's clipboard and instructs them to paste and run the command via the Windows Run dialog.

The pasted command is designed to extract and run a remote PowerShell payload.

According to Manifold Security, the domain has been serving the ClickFix lure since at least June 2026.

What happened

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.

Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure." As of writing, the domain has been marked as malicious and unsafe on both VirusTotal and Google's Safe Browsing list .

What changed

The tell only appears at request time, from the caller that matters." The disclosure comes as Manifold said it has since identified 13 more placeholder domains that are not IANA-reserved, with two of them – yoursite[.]com and your-domain[.]com – serving scams and scareware to macOS visitors and an ordinary parking page to other users.

Who is affected

ClickFix is a social engineering attack technique in which either malicious or legitimate-but-compromised websites display error messages, browser alerts, or CAPTCHA verification prompts, tricking users into copying and executing hidden commands via the Windows Run dialog or Terminal to "fix" the issue.

Please try again from a Windows device." A search on GitHub shows that the domain is referenced in over 1,700 public repositories, including those related to AI agent skills and MCP-server docs that cite "third-party[.]com" as an example endpoint.

Why it matters

To counter the threat, it's advised to audit their documentation and treat non-reserved placeholder domains (e.g., yourcompany[.]com, mycompany[.]com, your-api[.]com, and their lookalikes) as squattable and open to abuse by threat actors, who can register them and serve malicious content.

Often, web pages using ClickFix rely on clipboard hijacking to automatically inject malicious script or commands into the victim's clipboard for subsequent pasting on Windows Run dialog or macOS Terminal.

Technical details

Windows users visiting the page are shown a Cloudflare check that poisons the victim's clipboard and instructs them to paste and run the command via the Windows Run dialog.

The pasted command is designed to extract and run a remote PowerShell payload.

Response

According to Manifold Security, the domain has been serving the ClickFix lure since at least June 2026.

Developers working on skills, documentation, or test cases are recommended to use reserved placeholders like "example[.]com" (or "example[.]org," "example[.]net") only and avoid using plausible-sounding domains that are not under their control.

Attribution

The Hacker News: The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.

What to watch next

Watch for updated vendor guidance and fixed-version details.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility ToolsThe Hacker News · 2 Oct 2026, 4:45 pmMicrosoft is rolling out Linux container support to WSLBleepingComputer · 30 Sept 2026, 6:10 am57% of security execs report challenges with onboarding entry-level staffSC Media · 30 Sept 2026, 12:49 amDutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters InvestigationThe Hacker News · 29 Sept 2026, 6:56 pm