- The long-trusted documentation placeholder domain “third-party[.]com” has been weaponized to serve a ClickFix malware lure to Windows users.
- Unlike “example[.]com,” the domain was not IANA-reserved and was registered by an attacker to serve malicious payloads from a previously trusted source.
- Manifold Security identified 13 additional non-reserved placeholder domains, including “yoursite[.]com” and “your-domain[.]com,” which are serving scams and scareware.
The “third-party[.]com” domain, a widely used placeholder in software documentation for years, has been hijacked to deploy a ClickFix social engineering attack targeting Windows browsers while showing harmless decoys to others. According to Manifold Security, researchers discovered that the domain, which is not IANA-reserved, was registered by an unknown actor who now serves malicious content from the trusted address.
“This is now a live pointer to a ClickFix server,” said Ax Sharma, Head of Research at Manifold Security. The attack relies on clipboard hijacking to inject malicious commands, tricking users into pasting and executing the code via the Windows Run dialog. The domain has been flagged as malicious on VirusTotal and Google’s Safe Browsing list.
Meanwhile, macOS users visiting the page are shown a fake security prompt that simply states, “macOS is not supported.” The danger is amplified by the domain’s presence in over 1,700 public GitHub repositories, including AI agent skills and documentation that cite it as a valid example endpoint.
A file scan cannot detect the threat, as the malicious payload only appears when a Windows user’s agent requests the page. Manifold Security has since identified 13 more vulnerable placeholder domains like “your-domain[.]com” and “yoursite[.]com,” which are serving scareware and investment scams to macOS users.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
