Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
AI-summarised brief · reviewed before publication
The domain “third‑party.com,” long used as a generic documentation placeholder, has been hijacked to serve a ClickFix lure targeting Windows browsers while displaying a benign decoy to other users. Manifold Security reports the site has been active since June 2026, poisoning Windows users’ clipboards with a command that downloads a remote PowerShell payload. The domain appears in over 1,700 GitHub repositories, including AI‑agent skills and documentation, turning a trusted placeholder into a malicious vector. The site is now flagged as unsafe on VirusTotal and Google Safe Browsing.
💡 Why It Matters
- · Attackers weaponize widely trusted placeholder domains, turning innocuous documentation references into stealthy delivery points for clipboard‑based malware.
- · This exposes developers and enterprises to hidden threats that bypass static code reviews and standard security checks.