third-party.com placeholder domain hijacked to spread ClickFix malware
Security researchers at Manifold Security found that third-party.com, a domain frequently used as a generic placeholder in developer documentation and code samples, now hosts a fake Cloudflare verification page. BleepingComputer confirmed the page mimics a 'Performing security verification' CAPTCHA that copies a malicious PowerShell command to a user's clipboard, then instructs them to paste and run it via Windows key + R, which downloads and executes malware from an external URL.
GoKawiil's interpretation of the reporting above, not reported fact.
Because third-party.com is a real, ownable domain rather than an IANA-reserved placeholder like example.com, anyone referencing it in tutorials, AI agent skills, or MCP server docs could unwittingly send readers to a live attack page. This suggests developers should avoid using non-reserved domains as stand-ins, since ownership of such domains can change and be weaponized without warning. It also highlights the growing use of ClickFix-style social engineering, which relies on victims manually executing commands rather than downloading files.
- third-party.com, widely used as a documentation placeholder, now hosts a malicious fake Cloudflare CAPTCHA page.
- The attack tricks users into pasting a PowerShell command via Windows key + R, which downloads and runs malware.
- Unlike example.com/net/org, third-party.com is not IANA-reserved, meaning its content can change and be exploited.
YubiKey 5C NFC Security Key — With phishing and ClickFix-style social engineering attacks tricking users into running malicious commands, hardware-based authentication is a strong line of defense for your critical accounts. A YubiKey adds a physical verification step that malware and fake CAPTCHA pages simply can't fake or bypass.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-23
Published there as: “Placeholder domain used in dev docs now serves ClickFix attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.