third-party.com placeholder domain hijacked to spread ClickFix malware
Security researchers at Manifold Security found that third-party.com, a domain frequently used as a generic placeholder in developer documentation and code samples, now hosts a fake Cloudflare verification page. BleepingComputer confirmed the page mimics a 'Performing security verification' CAPTCHA that copies a malicious PowerShell command to a user's clipboard, then instructs them to paste and run it via Windows key + R, which downloads and executes malware from an external URL.