Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » third-party.com ClickFix attack exploits a placeholder nobody reserved
    Technology

    third-party.com ClickFix attack exploits a placeholder nobody reserved

    Gary BehanBy Gary Behan04/10/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    third-party.com ClickFix attack
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    The domain third-party.com, long treated as a generic placeholder in developer documentation, is now serving a third-party.com ClickFix attack that impersonates a Cloudflare security check and attempts to trick Windows users into running malicious PowerShell commands. As The Hacker News reported, the domain has been serving the lure since at least June 2026.

    Manifold Security first flagged the issue after discovering the malicious page while examining public AI skills and MCP server documentation that referenced the domain. BleepingComputer subsequently confirmed that visitors to third-party.com are served a fake Cloudflare ‘Performing security verification’ CAPTCHA screen, complete with a ‘Verify you are human’ prompt. Clicking the verification box silently copies a malicious PowerShell command into the Windows Clipboard. The page then instructs the visitor to press Windows key + R, paste with Ctrl+V, and hit Enter. If they comply, the command reconstructs a payload URL, downloads a PowerShell script, and executes it.

    Why third-party.com is a particularly sharp lure

    The choice of domain is what makes this campaign worth paying attention to. Unlike example.com, example.net, and example.org, which IANA reserves specifically for documentation and cannot be registered or transferred, third-party.com is an ordinary registered domain whose owner controls its content. It has been treated as a stand-in for an arbitrary external service in documentation from bodies including the W3C, in Chromium’s own developer docs, and across PrivacyCG proposals on GitHub.

    Manifold Security puts the scale of that exposure bluntly: a public code search turns up the domain in over 1,500 files across 1,700+ repositories, from projects associated with names including Chromium, Sanity, and Vercel. A 2015 Stack Overflow question captures the practical risk neatly: a developer had copied an asynchronous loading example containing https://third-party.com/resource.js into a live site before realising it was making real network requests to a real domain.

    None of those documentation projects are compromised. The concern is that applications or test code which copied placeholder URLs verbatim could cause a browser or automated tool to contact third-party.com and display the ClickFix page without any deliberate action by a user.

    A payload chain that worked, then broke

    At the time of BleepingComputer’s testing, the downstream payload domain, elxxvvx[.]xyz, had stopped resolving, leaving the attack chain broken. A Hybrid Analysis report from 2 May 2026 shows that while it was active, the site distributed a PowerShell script that downloaded a 134MB zip archive, saved it as update26.zip, extracted it, and attempted to launch an executable named draw.io.exe. Because the archive is no longer available, what the final payload does remains unknown.

    The campaign is Windows-only by design. Manifold’s Ax Sharma notes that macOS and Linux visitors receive a near-identical page that halts at an error: ‘macOS is not supported. This website requires a Windows PC to access.’ No clipboard poisoning, no payload. As Sharma puts it, ‘The attacker only shows the weapon to the targets it works against, which is precisely why a casual look, or a scanner on a Linux datacenter IP, sees nothing wrong.’

    The domain itself was first registered in 1996, well before the current campaign began, and BleepingComputer has not determined when or how control of the site changed. There are no reports yet that references to third-party.com in documentation have resulted in ClickFix attacks executing on developers’ devices or within their applications.

    ClickFix is surging as a delivery method

    The broader context matters here. According to Push Security, ClickFix attacks have risen 400% year-over-year, with a separate study they cite recording a 517% surge in just the last six months. The technique’s appeal to attackers is straightforward: because the malware is installed via commands the user executes themselves rather than via a downloaded file or email attachment, it can in some cases bypass traditional antivirus software.

    The scale of that problem is laid out in detail on the Microsoft Security Blog, which notes that Microsoft Defender Experts observed thousands of devices being affected by a ClickFix attack per month in early 2025, even on machines running an endpoint detection and response (EDR) solution.

    As Aviatrix Threat Research Center documents, the third-party.com campaign is a sharp illustration of a wider pattern: attackers do not always need to compromise a trusted project directly. Squatting on an unreserved domain that trusted projects happen to reference in their examples is a lower-effort route to the same result. While the current payload chain is broken, the domain remains live and could be pointed at a new payload at any point.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleAI Agents Credit Card Skimmers Hit 119 Sites and Stole 600K Records
    Next Article Windows File History backup bug patched in September preview updates
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Anthropic Offers Free Credits for Claude Code Cloud Sessions, With a Catch

    06/10/2026

    Rydox marketplace guilty plea lands Kosovar admin facing 22 years

    06/10/2026

    Bitget North Korea crypto hack: stolen funds revised up to $387.5 million

    06/10/2026

    MacSync Malware Uses iCloud Calendar Events to Stage New Payloads

    05/10/2026

    GitLab email token exposure lets attackers open merge requests as you

    05/10/2026

    FedRAMP VDR VER Compliance: What the December Deadline Actually Demands

    05/10/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.