Widely Used Developer Placeholder Domain third-party.com Now Hosts ClickFix Malware

3 min read
Source: BleepingComputer
Widely Used Developer Placeholder Domain third-party.com Now Hosts ClickFix Malware
Photo: BleepingComputer
TL;DR

The domain third-party.com, a common placeholder in developer documentation, is now serving a fake Cloudflare verification page that tricks Windows users into executing malicious PowerShell commands. This ClickFix attack exploits the fact that the domain is not reserved for documentation like example.com, allowing attackers to hijack it for malware distribution. While the current payload is broken, the infrastructure remains live, posing a risk if reactivated.

Key points

  • third-party.com serves a fake Cloudflare CAPTCHA that copies a malicious PowerShell command to the clipboard.
  • The attack targets Windows users; macOS and Linux visitors see an 'unsupported' error, hiding the threat from scanners.
  • The domain is used in over 1,500 files across 1,700+ repositories, including trusted projects like Chromium and Vercel.
  • Unlike example.com, third-party.com is a registered domain not protected by IANA, making it vulnerable to hijacking.
  • The current payload URL is broken, but the ClickFix lure remains live, posing a potential future threat.

Background

ClickFix attacks have surged in 2026, becoming a leading initial-access technique for enterprise intrusions. Previous coverage noted that these attacks often use blockchain-hosted infrastructure and fake CAPTCHAs to bypass traditional defenses. The current incident highlights a new vector: the compromise of a widely used documentation placeholder domain, which could expose developers and automated tools to malicious content if they copy examples literally.

How outlets are covering it

BleepingComputer and Manifold Security focus on the specific compromise of third-party.com, emphasizing the risk to developers who copy documentation examples. They note that while the current payload is broken, the domain remains live and could be reactivated. The Hacker News (CTM360) provides a broader view, highlighting ClickFix as the most common initial-access technique, with 47% of Microsoft Defender cases in 2025 attributed to it. They emphasize the resilience of ClickFix infrastructure, including blockchain-based domain resolution, and the importance of user awareness and clipboard restrictions. CyberScoop’s podcast discusses the evolution of ClickFix into variants like FileFix and 'consent fix,' noting that state-sponsored actors like APT28 and Lazarus Group are now using the technique. All sources agree that traditional defenses like antivirus and domain blocking are ineffective against ClickFix, and that user education and technical controls like clipboard restrictions are critical.

Why it matters

The compromise of third-party.com highlights a critical gap in the security of developer documentation and placeholder domains. As developers and automated tools increasingly rely on these domains for examples, a single hijacked domain could expose thousands of systems to malware. The ClickFix technique bypasses traditional defenses by leveraging user trust and native system binaries, making it a persistent and evolving threat. Organizations must update their security practices to include clipboard restrictions, authenticated proxies for script execution, and user awareness training to mitigate ClickFix risks.

What to watch

Monitor third-party.com for any changes in its content or payload, as the domain remains live and could be reactivated with a new malicious payload. Update developer documentation and codebases to replace third-party.com with reserved domains like example.com or example.net. Implement technical controls such as clipboard-write blocking in managed browsers and authenticated proxies for script interpreters. Conduct user awareness training to educate employees about ClickFix attacks and the importance of not pasting commands from untrusted sources. Review and update security policies to address the evolving nature of ClickFix and other social engineering attacks.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer