{"id":3131,"date":"2026-09-24T17:06:56","date_gmt":"2026-09-24T17:06:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3131"},"modified":"2026-09-24T17:06:56","modified_gmt":"2026-09-24T17:06:56","slug":"placeholder-third-party-com-referenced-across-1700-repositories-now-serves-malicious-content","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3131","title":{"rendered":"Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhy4aXDWSC5cKzOZO8lRbk8o5I1fHPlCGbfxxYL6tyJxauEL-8EVj7-AypDhYt_Wg6bDLqlj0UK4LrGJdeI4ChsksaB6tTZxo8ikCLdwC0wjRfJPE_Z1qM_CVUg7s1ORdmWW2XTDtlPPDcI8JvelrbmJhcjVthnqYWQrZ7ySnIMMPRZfa_VzgaBCWyWc_JJ\/s1700-nu-rw-lo-l85-e365\/third.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>The \u00abthird-party[.]com\u00bb domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.<\/p>\n<p>\u00abthird-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,\u00bb Manifold Security&#8217;s Head of Research, Ax Sharma, <a href=\"https:\/\/www.manifold.security\/blog\/third-party-com-placeholder-clickfix\" target=\"_blank\">said<\/a>. \u00abUnlike &#8216;example[.]com,&#8217; third-party[.]com is not <a href=\"https:\/\/www.iana.org\/domains\/reserved\" target=\"_blank\">IANA-reserved<\/a>. Anyone could register it, and someone did. Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure.\u00bb<\/p>\n<p>As of writing, the domain has been marked as malicious and unsafe on both <a href=\"https:\/\/www.virustotal.com\/gui\/domain\/third-party.com\" target=\"_blank\">VirusTotal<\/a> and Google&#8217;s <a href=\"https:\/\/transparencyreport.google.com\/safe-browsing\/search?url=third-party.com&amp;hl=en\" target=\"_blank\">Safe Browsing list<\/a>.<\/p>\n<p>ClickFix is a <a href=\"https:\/\/www.group-ib.com\/blog\/clickfix-the-social-engineering-technique-hackers-use-to-manipulate-victims\/\" target=\"_blank\">social engineering attack<\/a> technique in which either malicious or legitimate-but-compromised websites display error messages, browser alerts, or CAPTCHA verification prompts, tricking users into <a href=\"https:\/\/www.halcyon.ai\/ransomware-research-reports\/clipboard-to-encryption-the-critical-role-of-clickfix-in-ransomware-campaigns\" target=\"_blank\">copying and executing hidden commands<\/a> via the Windows Run dialog or Terminal to \u00abfix\u00bb the issue.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Often, web pages using ClickFix rely on clipboard hijacking to automatically inject malicious script or commands into the victim&#8217;s clipboard for subsequent pasting on Windows Run dialog or macOS Terminal. This approach is also sometimes referred to as pastejacking.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>According to Manifold Security, the domain has been serving the ClickFix lure since at least June 2026. Windows users visiting the page are shown a Cloudflare check that poisons the victim&#8217;s clipboard and instructs them to paste and run the command via the Windows Run dialog. The pasted command is designed to extract and run a remote PowerShell payload.<\/p>\n<p>When a macOS user visits the same page, the fake security verification prompt shows an error: \u00abmacOS is not supported. This website requires a Windows PC to access. Please try again from a Windows device.\u00bb<\/p>\n<p>A search on GitHub shows that the domain is <a href=\"https:\/\/github.com\/search?q=third-party.com&amp;type=code\" target=\"_blank\">referenced<\/a> in over 1,700 public repositories, including those related to AI agent skills and MCP-server docs that cite \u00abthird-party[.]com\u00bb as an example endpoint.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6FqmwDHOsb9pXyzBWm8SaBshhBvE3r8M92yyLgbKD2dxbXKl_uqwPhab2oBIViZWRKPqBWi6JNfJcjhop_8AHbN3paxONeY_7LulW3huATNeCkrLGWiHjZe0Wz9_esPCfAhT30cZC0egKtEntiavR1gI-E_YIwBPp82dTBO6JCANdz55TS2K6ioYW1j1y\/s1700-nu-rw-lo-l85-e365\/1000110911.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6FqmwDHOsb9pXyzBWm8SaBshhBvE3r8M92yyLgbKD2dxbXKl_uqwPhab2oBIViZWRKPqBWi6JNfJcjhop_8AHbN3paxONeY_7LulW3huATNeCkrLGWiHjZe0Wz9_esPCfAhT30cZC0egKtEntiavR1gI-E_YIwBPp82dTBO6JCANdz55TS2K6ioYW1j1y\/s1700-nu-rw-lo-l85-e365\/1000110911.jpg\" alt=\"\" border=\"0\" data-original-height=\"2304\" data-original-width=\"2400\"\/><\/a><\/div>\n<p>\u00abIn every one of those places it is exactly what it looks like: a placeholder, an example, a stand-in, and entirely reasonable use by the teams involved,\u00bb Sharma noted. \u00abIt is also, now, a live pointer to a ClickFix server.\u00bb<\/p>\n<p>This weaponization of a blindly trusted domain, in turn, <a href=\"https:\/\/www.manifold.security\/blog\/curl-bash-ai-agents\" target=\"_blank\">can open up avenues<\/a> for prompt injection and other unintended behaviors.<\/p>\n<p>To counter the threat, it&#8217;s advised to audit their documentation and treat non-reserved placeholder domains (e.g., yourcompany[.]com, mycompany[.]com, your-api[.]com, and their lookalikes) as squattable and open to abuse by threat actors, who can register them and serve malicious content.<\/p>\n<p>Developers working on skills, documentation, or test cases are recommended to use reserved placeholders like \u00abexample[.]com\u00bb (or \u00abexample[.]org,\u00bb \u00abexample[.]net\u00bb) only and avoid using plausible-sounding domains that are not under their control.<\/p>\n<p>\u00abYou can scan the skill, read the file, resolve the domain from your analysis box, and conclude it is fine, and be completely wrong about what a Windows user&#8217;s agent receives when it follows the same link,\u00bb Manifold Security pointed out. \u00abA file scan cannot see what a website decides to send. The tell only appears at request time, from the caller that matters.\u00bb<\/p>\n<p>The disclosure comes as Manifold said it has since identified 13 more placeholder domains that are not IANA-reserved, with two of them \u2013 yoursite[.]com and your-domain[.]com \u2013 serving scams and scareware to macOS visitors and an ordinary parking page to other users.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abOn a macOS browser, your-domain[.]com showed a fake &#8216;MacOS Security Center&#8217; claiming four viruses and selling a counterfeit McAfee renewal at 55% off,\u00bb security researcher Cody Nash <a href=\"https:\/\/www.manifold.security\/blog\/placeholder-domains-ads-serve-scams\" target=\"_blank\">said<\/a>. \u00abOn another macOS render, yoursite[.]com showed a counterfeit ZDF news article advertising an investment scheme.\u00bb<\/p>\n<p>The complete list of domains, each of them are pass static checks, is as follows &#8211;<\/p>\n<ul>\n<li>your-domain[.]com<\/li>\n<li>yourdomain[.]com<\/li>\n<li>your-site[.]com<\/li>\n<li>yoursite[.]com<\/li>\n<li>your-app[.]com<\/li>\n<li>yourapp[.]com<\/li>\n<li>myapp[.]com<\/li>\n<li>mysite[.]com<\/li>\n<li>acme[.]com<\/li>\n<li>company[.]com<\/li>\n<li>mycompany[.]com<\/li>\n<li>vendor[.]com<\/li>\n<li>foo[.]com<\/li>\n<\/ul>\n<p>To make matters worse, the two scam-scarware-serving sites are present in hundreds of thousands of GitHub files and hundreds of agent skills. \u00abScareware and investment fraud are a lower threat than clipboard malware, the exposure they ride on is far larger, and none of it showed up in any static check we ran,\u00bb Nash said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The \u00abthird-party[.]com\u00bb domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. \u00abthird-party[.]com has been&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3132,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1879,33,3537,3539,1738,3540,3538],"class_list":["post-3131","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-content","tag-malicious","tag-placeholder","tag-referenced","tag-repositories","tag-serves","tag-thirdparty-com"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3131"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3131\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3132"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}