Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.
![Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content](/api/image?url=https%3A%2F%2Fblogger.googleusercontent.com%2Fimg%2Fb%2FR29vZ2xl%2FAVvXsEhy4aXDWSC5cKzOZO8lRbk8o5I1fHPlCGbfxxYL6tyJxauEL-8EVj7-AypDhYt_Wg6bDLqlj0UK4LrGJdeI4ChsksaB6tTZxo8ikCLdwC0wjRfJPE_Z1qM_CVUg7s1ORdmWW2XTDtlPPDcI8JvelrbmJhcjVthnqYWQrZ7ySnIMMPRZfa_VzgaBCWyWc_JJ%2Fs1700-nu-rw-lo-l85-e365%2Fthird.jpg)
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.
Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure." As of writing, the domain has been marked as malicious and unsafe on both VirusTotal and Google's Safe Browsing list .
The tell only appears at request time, from the caller that matters." The disclosure comes as Manifold said it has since identified 13 more placeholder domains that are not IANA-reserved, with two of them – yoursite[.]com and your-domain[.]com – serving scams and scareware to macOS visitors and an ordinary parking page to other users.
ClickFix is a social engineering attack technique in which either malicious or legitimate-but-compromised websites display error messages, browser alerts, or CAPTCHA verification prompts, tricking users into copying and executing hidden commands via the Windows Run dialog or Terminal to "fix" the issue.
Please try again from a Windows device." A search on GitHub shows that the domain is referenced in over 1,700 public repositories, including those related to AI agent skills and MCP-server docs that cite "third-party[.]com" as an example endpoint.
To counter the threat, it's advised to audit their documentation and treat non-reserved placeholder domains (e.g., yourcompany[.]com, mycompany[.]com, your-api[.]com, and their lookalikes) as squattable and open to abuse by threat actors, who can register them and serve malicious content.
Often, web pages using ClickFix rely on clipboard hijacking to automatically inject malicious script or commands into the victim's clipboard for subsequent pasting on Windows Run dialog or macOS Terminal.
Windows users visiting the page are shown a Cloudflare check that poisons the victim's clipboard and instructs them to paste and run the command via the Windows Run dialog.
The pasted command is designed to extract and run a remote PowerShell payload.
According to Manifold Security, the domain has been serving the ClickFix lure since at least June 2026.
What happened
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.
Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure." As of writing, the domain has been marked as malicious and unsafe on both VirusTotal and Google's Safe Browsing list .
What changed
The tell only appears at request time, from the caller that matters." The disclosure comes as Manifold said it has since identified 13 more placeholder domains that are not IANA-reserved, with two of them – yoursite[.]com and your-domain[.]com – serving scams and scareware to macOS visitors and an ordinary parking page to other users.
Who is affected
ClickFix is a social engineering attack technique in which either malicious or legitimate-but-compromised websites display error messages, browser alerts, or CAPTCHA verification prompts, tricking users into copying and executing hidden commands via the Windows Run dialog or Terminal to "fix" the issue.
Please try again from a Windows device." A search on GitHub shows that the domain is referenced in over 1,700 public repositories, including those related to AI agent skills and MCP-server docs that cite "third-party[.]com" as an example endpoint.
Why it matters
To counter the threat, it's advised to audit their documentation and treat non-reserved placeholder domains (e.g., yourcompany[.]com, mycompany[.]com, your-api[.]com, and their lookalikes) as squattable and open to abuse by threat actors, who can register them and serve malicious content.
Often, web pages using ClickFix rely on clipboard hijacking to automatically inject malicious script or commands into the victim's clipboard for subsequent pasting on Windows Run dialog or macOS Terminal.
Technical details
Windows users visiting the page are shown a Cloudflare check that poisons the victim's clipboard and instructs them to paste and run the command via the Windows Run dialog.
The pasted command is designed to extract and run a remote PowerShell payload.
Response
According to Manifold Security, the domain has been serving the ClickFix lure since at least June 2026.
Developers working on skills, documentation, or test cases are recommended to use reserved placeholders like "example[.]com" (or "example[.]org," "example[.]net") only and avoid using plausible-sounding domains that are not under their control.
Attribution
The Hacker News: The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.
What to watch next
Watch for updated vendor guidance and fixed-version details.