The third-party[.]com domain, long used as a documentation placeholder, has been hijacked to deliver a ClickFix lure to Windows users while showing benign content to others. Manifold Security also found 13 additional non-reserved placeholder domains being abused for scams and scareware, highlighting the risk of hard-coded example domains in docs and agent skills. #third-partycom #ClickFix #ManifoldSecurity #VirusTotal #GoogleSafeBrowsing #yourdomaincom #yoursitecom
Keypoints
- third-party[.]com was weaponized to serve a ClickFix lure.
- Windows visitors were shown a fake Cloudflare check that poisoned the clipboard.
- The pasted command was designed to run a remote PowerShell payload.
- macOS users saw a fake unsupported-browser message or scam content instead.
- Manifold Security urged using reserved placeholders like example[.]com only.
Read More: https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html