Squatted docs placeholder third-party.com served ClickFix PowerShell lures across 1,700+ repositories
Attackers registered the unreserved documentation placeholder third-party.com, referenced in 1,700+ GitHub repositories, and since at least June 2026 have served Windows visitors a fake Cloudflare ClickFix page that clipboard-poisons a PowerShell downloader…
Manifold Security found that third-party.com — an unreserved, non-IANA documentation placeholder long hardcoded in W3C, Chromium, Vercel, Sanity, MCP-server, and AI agent-skills documentation and referenced in more than 1,700 GitHub repositories (over 1,500 files, per BleepingComputer) — has served a Windows-targeted ClickFix lure since at least June 2026. The page imitates a Cloudflare 'Verify you are human' check, copies a PowerShell command to the clipboard, and tells victims to paste it into the Windows Run dialog (Win+R) to fetch and execute a remote payload. BleepingComputer, the only outlet to trace the chain, says the command pulled a script from elxxvvx[.]xyz — non-resolving at time of writing — that in a May 2026 sample downloaded a 134MB zip archive launching an executable named draw.io.exe; no victim executions have been confirmed. Sources disagree on non-Windows behavior: BleepingComputer says Linux and macOS visitors receive only an 'unsupported' error, while The Hacker News says they see a decoy page or that message. The Hacker News adds that the domain is flagged by VirusTotal and Google Safe Browsing, and that related placeholders yoursite.com and your-domain.com serve macOS scareware and investment-fraud pages in far larger numbers of files. CSO Online reports that ESET measured a 108 percent rise in ClickFix detections between late 2025 and early 2026, and that the domain was reported to registrar Network Solutions even as the lure remained active. Malwarebytes contrasts third-party.com with the reserved placeholder example.com, noting it is an ordinary registrable domain anyone could own.
- Domain: third-party.com, an unreserved, non-IANA documentation placeholder (unlike the reserved example.com), researched by Manifold Security
- Reach: referenced in 1,700+ GitHub repositories and over 1,500 files, including W3C, Chromium, Vercel, Sanity, MCP-server, and AI agent-skills documentation
- Timeline: ClickFix lure served since at least June 2026
- Mechanics: fake Cloudflare 'Verify you are human' CAPTCHA poisons the clipboard with a PowerShell command; victims instructed to paste it into the Windows Run dialog (Win+R), downloading and executing a remote payload
- Payload: script hosted at elxxvvx[.]xyz (non-resolving at time of writing); a May 2026 sample downloaded a 134MB zip archive launching an executable named draw.io.exe; no confirmed victim executions
- Disagreement: Linux/macOS visitors get an 'unsupported' error (BleepingComputer) versus a decoy page or that message (The Hacker News)
- Reputation: domain flagged by VirusTotal and Google Safe Browsing; related placeholders yoursite.com and your-domain.com serve macOS scareware and investment-fraud pages in far larger numbers of files (The Hacker News)
- Context: ESET measured a 108 percent rise in ClickFix detections between late 2025 and early 2026 (CSO Online)
Coverage timelineoldest first · each row is one article
- · 3d agoPlaceholder domain used in dev docs now serves ClickFix attacks
BleepingComputer· 55
Placeholder domain third-party.com, referenced across 1,700+ repositories, now serves fake Cloudflare ClickFix pages pushing clipboard-copied PowerShell commands at Windows users.
- · 2d agoPlaceholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The Hacker News· 76
Squatted placeholder domain third-party.com now serves a Windows ClickFix lure referenced in over 1,700 repositories.
- · 1d agoCriminals turn placeholder domain into ClickFix trap
Malwarebytes Labs· 45