A commonly used documentation placeholder domain has been observed serving malicious ClickFix lures after being registered and repurposed by unknown actors. Security researchers from Manifold Security reported that the third-party.com domain, which had traditionally been used as an example address in documentation and testing materials, is now being used to display fake verification pages designed to trick Windows users into executing harmful commands. The discovery highlights the risks associated with using non reserved placeholder domains in technical documentation, development environments, and AI related resources, as attackers can potentially register these domains and redirect users toward malicious infrastructure.
According to Manifold Security Head of Research Ax Sharma, third-party.com had served a similar purpose to example.com for years, but unlike officially reserved example domains, it was not protected under IANA reserved domain policies. This allowed an individual or group to register the domain and use it for malicious purposes. Researchers found that the domain has been hosting a ClickFix campaign since at least June 2026. ClickFix is a social engineering technique where attackers display fake browser alerts, CAPTCHA pages, or security verification screens that encourage users to copy and execute commands through tools such as the Windows Run dialog or terminal applications. In this campaign, Windows users visiting the domain were shown a fake Cloudflare verification page that manipulated the clipboard and inserted a command designed to download and execute a remote PowerShell payload.
The malicious activity was designed to appear differently depending on the operating system being used. Researchers said Windows visitors were presented with instructions encouraging them to paste the copied command into the Windows Run dialog, while macOS users received an error message claiming that the website required a Windows device. The clipboard manipulation technique used in such attacks is sometimes referred to as pastejacking because it relies on convincing users to execute content that has already been placed into their clipboard without their direct awareness. Security researchers noted that the attack method depends heavily on user interaction, making awareness and caution important factors in preventing compromise.
A major concern identified by researchers is the widespread use of third-party.com in public repositories and technical resources. A GitHub search showed that the domain appeared in more than 1,700 public repositories, including documentation related to AI agent skills and Model Context Protocol (MCP) server resources where it had been used as an example endpoint. Researchers explained that these references were originally legitimate placeholder uses, but they now point users toward attacker controlled infrastructure. This creates potential risks for developers, automated tools, and AI systems that may process documentation or follow links without recognizing that a previously harmless example domain has changed ownership and behaviour.
Manifold Security advised developers and organizations to review documentation, code samples, and testing materials to identify placeholder domains that are not officially reserved or controlled by their owners. Researchers recommended using reserved domains such as example.com, example.org, and example.net when creating examples instead of realistic looking domains that could later be registered by unrelated parties. The company also warned that static security checks may not always detect such risks because the malicious behaviour only appears when a user or automated system accesses the live website. Beyond third-party.com, researchers identified additional placeholder style domains that were serving scams or misleading content, including yoursite.com and your-domain.com. The findings demonstrate the importance of careful domain selection in technical resources and highlight how attackers can exploit trusted references to distribute malware, phishing pages, and other harmful content.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





