importantSYS.SOURCE: The Hacker News• 2026-09-24T20:57:32+05:30
Malicious Use of Placeholder Domain third-party.com in Over 1,700 Repositories
The domain third-party.com, used as a placeholder in over 1,700 repositories, has been weaponized to serve ClickFix malware targeting Windows users and fake security prompts for macOS. Security researchers warn of risks from unreserved placeholder domains and recommend using IANA-reserved examples like example.com.
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.
"third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com
*** END OF TRANSMISSION ***