The domain "third-party.com", frequently used in developer documentation and code examples as a generic external website, API, or service placeholder, has been compromised. Unlike reserved domains such as example.com, example.net, and example.org, "third-party.com" is a regularly registered domain, allowing its owner to control its content. This control has now been used maliciously.
The domain is currently serving a ClickFix attack, impersonating a Cloudflare security check. When users visit the site, they are presented with a fake Cloudflare "Performing security verification" CAPTCHA screen. After clicking a verification box, a malicious PowerShell command is copied to the user's Windows Clipboard. Users are then instructed to paste and execute this command, which downloads and runs a PowerShell script from an external URL.
This technique, known as ClickFix, relies on users manually executing commands, potentially bypassing traditional antivirus software. Manifold Security first reported this malicious activity after finding it referenced in public AI skills and MCP server documentation. BleepingComputer confirmed the presence of the fake Cloudflare page and the clipboard-based attack. While the current attack chain was broken at the time of testing due to the payload URL no longer resolving, past activity shows the distribution of a PowerShell script designed to download and execute a zip archive containing an executable.
The compromise of "third-party.com" highlights a security risk associated with using non-reserved domains as placeholders in documentation. Developers and users who interact with documentation referencing this domain could inadvertently be exposed to malware. This incident underscores the importance of using officially reserved domains for examples to prevent such vulnerabilities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The domain "third-party.com", commonly used as a placeholder in developer documentation, is now serving a fake Cloudflare verification page that attempts to trick Windows users into executing malicious PowerShell commands. This development is significant because it turns a widely accepted documentation practice into a security vulnerability, potentially exposing developers and users to malware through a trusted, yet compromised, resource.