Placeholder domain used in dev docs now serves ClickFix attacks
The domain "third-party.com," widely used as a placeholder in developer documentation, is now being exploited to serve ClickFix attacks that trick Windows users into executing malicious PowerShell commands.
Intelligence analysis by Gemini 2.5 Flash

A domain commonly found in developer documentation, third-party.com, has been weaponized to deliver ClickFix attacks. This involves impersonating a Cloudflare security check to prompt users to copy and execute a PowerShell command, which then downloads and runs malware, bypassing traditional security measures.
Imagine you're building with LEGOs and the instructions tell you to use a 'mystery block' from a friend's house. But someone sneaky changed what that 'mystery block' actually is, and now it's a trick that tries to make you do something bad on your computer, like installing a toy that isn't safe. This story is about how a website that was supposed to be a harmless 'mystery block' for computer builders turned into a trap.
Analysis
third-party.com
The domain third-party.com has long served as a generic placeholder in developer documentation and code examples, akin to example.com. However, unlike example.com, example.net, and example.org, which are specifically reserved by IANA for documentation purposes, third-party.com lacks such protection. This crucial distinction meant the domain could be registered and controlled by any entity, making it a prime target for malicious actors. Its widespread, uncritical adoption across various public developer resources, including W3C specifications and Chromium documentation, created a fertile ground for exploitation once it fell into the wrong hands. The article notes its appearance in over 1,500 files across 1,700+ repositories, underscoring the pervasive nature of its use and the potential reach of any attack leveraging it.
ClickFix
The attack method employed, known as ClickFix, is a sophisticated social engineering technique designed to bypass conventional security defenses. Instead of relying on direct downloads or email attachments, attackers leverage fake errors, CAPTCHA prompts, or security verification pages to convince victims to manually execute commands. In this specific instance, the malicious third-party.com page impersonates a Cloudflare security check, instructing users to copy a PowerShell command to their clipboard and then paste and execute it via the Windows Run dialog. This user-initiated execution of commands can often circumvent antivirus software, which might not flag the initial interaction as malicious, only the subsequent payload download. The article confirms that the PowerShell command, once executed, attempts to download and run a further script from elxxvvx[.]xyz/f, demonstrating a multi-stage infection chain.
Manifold Security
Manifold Security played a pivotal role in uncovering this threat, initially reporting the malicious use of third-party.com after discovering it within public AI skills and MCP server documentation. Their analysis, particularly by Ax Sharma, revealed the targeted nature of the attack: it specifically targets Windows users, with macOS and Linux visitors receiving an error message stating their operating system is unsupported. This selective targeting is a key aspect of the attack's stealth, as it ensures that security scanners or casual observers operating on non-Windows systems (like many datacenter IPs) would see nothing amiss, allowing the malicious activity to persist undetected for longer. The discovery by Manifold Security underscores the importance of vigilant monitoring of commonly used, yet unreserved, internet infrastructure elements that can be weaponized in unexpected ways, highlighting a blind spot in current security practices related to developer documentation and placeholder domains.
Key points
- The domain "third-party.com," a common placeholder in developer documentation, is now serving ClickFix attacks.
- The attack impersonates a Cloudflare security check, tricking Windows users into executing malicious PowerShell commands.
- Unlike IANA-reserved domains like example.com, third-party.com lacked protection, making it vulnerable to registration and exploitation.
- The ClickFix technique bypasses traditional antivirus by having users manually execute commands, downloading malware from a secondary URL.
- Manifold Security discovered the attack, noting its specific targeting of Windows users to evade detection by non-Windows systems.
This incident could prompt greater awareness among developers and organizations regarding the security implications of using unreserved placeholder domains, potentially leading to a shift towards IANA-reserved domains or more secure practices. Increased scrutiny might also encourage IANA to reserve additional generic domains to prevent future exploitation.
The exploitation of a widely used placeholder domain like "third-party.com" sets a dangerous precedent, suggesting that other unreserved, commonly referenced domains could be similarly weaponized. This could lead to a proliferation of hard-to-detect ClickFix attacks, as developers and automated tools continue to inadvertently direct traffic to malicious sites.



