Placeholder domain used in dev docs now serves ClickFix attacks
Placeholder domain third-party.com, referenced across 1,700+ repositories, now serves fake Cloudflare ClickFix pages pushing clipboard-copied PowerShell commands at Windows users.
third-party.com, long used as a placeholder in W3C, Chromium, MCP server, and AI skills documentation and referenced in over 1,500 files across 1,700+ repositories, has been serving a ClickFix attack since at least June 2026. The page shows a fake Cloudflare 'Verify you are human' CAPTCHA that copies a malicious PowerShell command to the Windows clipboard, instructing users to run it via Windows+R; the command downloads and executes a script from elxxvvx[.]xyz (currently non-resolving). A May 2026 sample downloaded a 134MB zip archive launching an executable named draw.io.exe. Linux and macOS visitors receive an 'unsupported' error instead of the lure.