Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

Executive Summary

The domain third-party.com, traditionally used as a generic documentation placeholder, has been hijacked to serve a ClickFix lure targeting Windows browsers while displaying a harmless decoy to other users. The malicious activity was detected across more than 1,700 code repositories, indicating widespread exploitation of the placeholder domain. Security researchers warn that any use of third-party.com in documentation or code may inadvertently expose users to this phishing attack.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-24T15:27:32+00:00 - Category: threat-intel

Original Description: The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com

"We must embrace pain and burn it as fuel for our journey."

— Kenji Miyazawa
Source: The Hacker News