Home / Sep 25, 2026 / Story
0
#6 The Hacker News general September 24, 2026 at 15:27 UTC

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

By [email protected] (The Hacker News)

AI Summary

The domain third-party[.]com, historically used as a generic documentation placeholder across 1,700+ repositories, is now actively serving a ClickFix lure that delivers malicious PowerShell commands to Windows users while showing harmless content to other visitors. Manifold Security researcher Ax Sharma confirmed the domain had functioned like example.com for years before being weaponized. Developers who have embedded this domain in documentation, READMEs, or code examples may be unwittingly exposing users to malware delivery.

Relevance score: 82.0/100

# More from September 25