Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The third-party[.]com domain, long used as a documentation placeholder, has been hijacked to deliver a ClickFix lure to Windows users while showing benign content to others. Manifold Security also found 13 additional non-reserved placeholder domains being abused for scams and scareware, highlighting the risk of hard-coded example domains in docs and agent skills. #third-partycom #ClickFix #ManifoldSecurity #VirusTotal #GoogleSafeBrowsing #yourdomaincom #yoursitecom

Keypoints

  • third-party[.]com was weaponized to serve a ClickFix lure.
  • Windows visitors were shown a fake Cloudflare check that poisoned the clipboard.
  • The pasted command was designed to run a remote PowerShell payload.
  • macOS users saw a fake unsupported-browser message or scam content instead.
  • Manifold Security urged using reserved placeholders like example[.]com only.

Read More: https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html