Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
thehackernews.com Sep 24, 2026

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

AI-summarised brief · reviewed before publication

The domain “third‑party.com,” long used as a generic documentation placeholder, has been hijacked to serve a ClickFix lure targeting Windows browsers while displaying a benign decoy to other users. Manifold Security reports the site has been active since June 2026, poisoning Windows users’ clipboards with a command that downloads a remote PowerShell payload. The domain appears in over 1,700 GitHub repositories, including AI‑agent skills and documentation, turning a trusted placeholder into a malicious vector. The site is now flagged as unsafe on VirusTotal and Google Safe Browsing.

💡 Why It Matters

  • · Attackers weaponize widely trusted placeholder domains, turning innocuous documentation references into stealthy delivery points for clipboard‑based malware.
  • · This exposes developers and enterprises to hidden threats that bypass static code reviews and standard security checks.