#6
The Hacker News
general
September 24, 2026 at 15:27 UTC
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
By [email protected] (The Hacker News)
AI Summary
The domain third-party[.]com, historically used as a generic documentation placeholder across 1,700+ repositories, is now actively serving a ClickFix lure that delivers malicious PowerShell commands to Windows users while showing harmless content to other visitors. Manifold Security researcher Ax Sharma confirmed the domain had functioned like example.com for years before being weaponized. Developers who have embedded this domain in documentation, READMEs, or code examples may be unwittingly exposing users to malware delivery.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →