Placeholder domain used in dev docs now serves ClickFix attacks
Key Points:
- The domain third-party.com, commonly used as a placeholder in developer documentation, is currently hosting a fake Cloudflare verification page that tricks Windows users into running malicious PowerShell commands via a ClickFix attack.
- Unlike reserved documentation domains like example.com, third-party.com is a normally registered domain controlled by its owner, which has been exploited to serve a fake CAPTCHA that copies a harmful PowerShell command to the clipboard and instructs users to execute it manually.
- The attack specifically targets Windows users, while Linux and macOS visitors see an error message without any malicious payload, making it difficult to detect through casual inspection or automated scanning from non-Windows environments.
- Many trusted developer resources and specifications have used third-party.com as a generic example domain, leading to potential unintentional exposure if placeholder URLs are copied literally into code or applications.
- Although the current attack payload domain is inactive and no confirmed infections have been reported, the live status of third-party.com poses an ongoing risk of future malware distribution campaigns leveraging this widely referenced placeholder domain.