The domain “third-party.com,” typically used as a documentation placeholder, has been identified as serving a ClickFix lure targeting Windows users while presenting a benign facade to others. This alarming discovery was reported by Manifold Security, which highlighted that the domain is not IANA-reserved, allowing anyone to register it and potentially exploit it for malicious purposes.
As of now, “third-party.com” has been flagged as malicious on both VirusTotal and Google’s Safe Browsing list. The ClickFix technique, a form of social engineering, tricks users into executing hidden commands through error messages or alerts displayed on compromised websites.
According to Manifold Security, the domain has been active in serving these lures since at least June 2026. Windows users visiting the site encounter a Cloudflare check that manipulates their clipboard, instructing them to paste and execute a command that runs a remote PowerShell payload. In contrast, macOS users receive a message stating that the site requires a Windows PC, effectively steering them away from the malicious content.
Notably, “third-party.com” is referenced in over 1,700 public repositories on GitHub, including documentation related to AI agent skills. This widespread usage raises concerns about the potential for exploitation, as developers may inadvertently direct users to malicious infrastructure.
To mitigate risks, experts recommend that developers avoid using non-reserved placeholder domains and instead rely on IANA-reserved domains like “example.com.” This precaution can help prevent similar exploitation of trusted domains in the future. The situation underscores the importance of vigilance in cybersecurity practices, particularly regarding the use of placeholder domains.
For further details, refer to the full report by The Hacker News.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


