Placeholder Domain Third-Party[.]Com: A Growing Malware Threat in Developer Repositories
Placeholder Domain third-party[.]com Now a Live Malware Trap Hiding in 1,700+ Code Repositories
A documentation placeholder domain trusted blindly by developers for years has been quietly redirecting Windows users to a clipboard-hijacking malware campaign since at least June 2026 — and most static security scans cannot detect it.
The domain third-party[.]com — long used as a harmless stand-in URL in technical documentation, much like example.com — was registered by an unknown threat actor and weaponized to serve a ClickFix lure to Windows browsers while displaying benign content to all other visitors. The domain has since been flagged as malicious on both VirusTotal and Google's Safe Browsing list.
This incident highlights a largely overlooked attack surface: the assumption that familiar-sounding placeholder domains are inherently safe. They are not, and this campaign proves the consequences of that assumption can be severe.
How the Attack Works
ClickFix is a social engineering technique that tricks users into executing malicious commands on their own machines. Victims visiting third-party[.]com on a Windows browser are shown what appears to be a Cloudflare security verification prompt. Behind that prompt is a clipboard-poisoning mechanism that automatically injects a malicious command.
Users are then instructed to paste and run that command via the Windows Run dialog. The pasted command is designed to extract and execute a remote PowerShell payload — handing attackers potential control over the victim's system. Understanding the full range of malware types and how they infiltrate systems is essential context here, as clipboard-hijacking techniques like this one represent one of the more deceptive delivery mechanisms in active use today.
The attack is surgically targeted. When a macOS user visits the same page, they receive an error message stating: "macOS is not supported. This website requires a Windows PC to access. Please try again from a Windows device." This deliberate filtering helps the campaign avoid broad detection while maximising impact on its intended targets.
"A file scan cannot see what a website decides to send," Manifold Security warned in its disclosure. "The tell only appears at request time, from the caller that matters."
This is a critical point. Static analysis tools are blind to server-side conditional responses. The malicious content is never served unless the visitor meets the attacker's criteria — Windows operating system, browser user-agent, and likely additional fingerprinting signals. No file is written to disk until a victim manually executes the poisoned clipboard command, which means endpoint detection tools may also miss the initial infection vector entirely.
The Scale of the Exposure
A Domain Embedded Across Developer Ecosystems
The danger of this campaign lies not in the sophistication of the malware alone but in how deeply the domain is embedded in developer ecosystems. A search on GitHub reveals third-party[.]com is referenced in over 1,700 public repositories. Those repositories include projects tied to AI agent skills and MCP-server documentation — all citing the domain as a routine example endpoint.
Ax Sharma, Head of Research at Manifold Security, described the fundamental problem clearly. "Third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Sharma said. "Unlike example[.]com, third-party[.]com is not IANA-reserved. Anyone could register it, and someone did. Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure."
Unlike IANA-reserved domains such as example.com — which cannot be registered or weaponized — placeholder domains with plausible-sounding names exist in a dangerous grey zone. Developers assumed they were safe. Threat actors knew otherwise.
This weaponization also opens potential avenues for prompt injection attacks against AI agents that autonomously follow URLs embedded in documentation or skill files. As AI-assisted development pipelines become more prevalent, any domain reference embedded in training data, skill files, or automated workflows becomes a potential execution point — one that attackers can exploit without ever touching the developer's codebase directly.
13 More Placeholder Domains Identified as Threats
Manifold Security's investigation did not stop at third-party[.]com. Researchers have since identified 13 additional non-IANA-reserved placeholder domains actively serving malicious or deceptive content. Two of them — yoursite[.]com and your-domain[.]com — are already being used to run scareware and investment fraud schemes targeting macOS users while showing ordinary parking pages to everyone else.
Security researcher Cody Nash detailed the findings. "On a macOS browser, your-domain[.]com showed a fake 'MacOS Security Center' claiming four viruses and selling a counterfeit McAfee renewal at 55% off," Nash said. "On another macOS render, yoursite[.]com showed a counterfeit ZDF news article advertising an investment scheme."
The full list of flagged domains includes:
- your-domain[.]com and yourdomain[.]com
- your-site[.]com and yoursite[.]com
- your-app[.]com and yourapp[.]com
- myapp[.]com and mysite[.]com
- acme[.]com and company[.]com
- mycompany[.]com and vendor[.]com
- foo[.]com
The two scam-serving domains alone appear across hundreds of thousands of GitHub files and hundreds of AI agent skills. Nash noted the broader implication: "Scareware and investment fraud are a lower threat than clipboard malware, but the exposure they ride on is larger — and none of it showed up in any static check we ran."
Why Static Scans Miss This Entirely
The evasion technique used here is straightforward but effective. The server examines the incoming HTTP request — specifically the User-Agent header — and delivers entirely different content depending on the visitor's operating system and browser. This means automated scanners, link-checkers, and CI/CD pipeline validators running on Linux-based infrastructure will never see the malicious payload. They receive a clean response. Only a Windows browser triggers the ClickFix lure.
This class of website security threat is particularly difficult to detect at scale because it exploits the gap between how security tools request content and how real users encounter it. Without behavioural simulation across multiple operating systems and browser environments, these conditional attacks remain effectively invisible to conventional scanning.
What Organisations and Developers Should Do Now
Audit Placeholder Domains Across All Repositories and Documentation
Manifold Security is urging developers and security teams to audit all documentation and codebases for non-reserved placeholder domains. The recommended fix is straightforward: use only IANA-reserved domains such as example.com, example.org, or example.net when placeholder URLs are needed. Any plausible-sounding domain not explicitly under an organisation's control should be treated as a potential squatting target.
For a broader view of how campaigns like this fit into the threat landscape, structured approaches to threat management and risk reduction provide a useful framework for security teams looking to systematically address this class of vulnerability across their environments.
Treat Every External Domain Reference as an Attack Surface
For businesses and development teams managing large repositories or AI tooling pipelines, this disclosure is a reminder that trust assumptions baked into documentation can become active liabilities. Auditing placeholder URLs in codebases — a task that sounds mundane but proved urgently necessary here — is now a legitimate security priority.
Developers building AI agent skills should treat every external domain reference as a potential attack surface and validate that referenced domains are IANA-reserved before deployment. Given the scale of exposure revealed by this investigation — hundreds of thousands of files, across public repositories, AI skill libraries, and MCP-server documentation — the remediation effort required is substantial, but the alternative is leaving attacker infrastructure embedded in trusted developer resources indefinitely.
The core lesson of this campaign is not that a single domain was weaponized. It is that the entire category of informal placeholder domains has been treated as inherently trustworthy without any technical basis for that trust. Threat actors have clearly identified this assumption and are exploiting it. Until the developer community standardises on IANA-reserved domains for all placeholder usage, that attack surface will remain open.
For further guidance on IANA-reserved domains and their intended use, the Internet Assigned Numbers Authority's official documentation provides authoritative reference material on which domains are protected from registration and why.