Public repositories referencing the domain: 1,700+ (Source: Manifold Security research, reported by The Hacker News (September 2026))
A stand-in address becomes live infrastructure
For years, developers writing documentation, test cases, and code samples used "third-party[.]com" the way most people use "example.com" — a throwaway address to fill a blank. The difference, according to Manifold Security's Head of Research Ax Sharma, is that example.com is reserved by the internet's naming authority (IANA) so nobody can register it. third-party[.]com was never protected that way. Someone bought it, and it now serves a ClickFix attack to Windows browsers while showing an unrelated, harmless page to everyone else. VirusTotal and Google Safe Browsing have since flagged the domain as malicious.
How the page decides who to attack
Manifold's researchers say the domain has run the attack since at least June 2026. A Windows visitor is shown a fake Cloudflare verification screen that silently loads a malicious command onto their clipboard, then instructs them to paste and run it via the Windows Run dialog — a technique known as ClickFix, or pastejacking, that ends with a remote PowerShell payload executing on the machine. A macOS visitor to the identical page instead sees a message saying the site requires a Windows PC. The cloaking is deliberate: the page behaves differently depending on who — or what — is asking.
Why this reaches further than a bad link
The domain turns up not just in old blog posts and Stack Overflow snippets but inside AI agent skill files and MCP-server documentation, where it is cited as a generic example endpoint. Sharma noted that a routine code or file review would miss the problem entirely: "You can scan the skill, read the file, resolve the domain from your analysis box, and conclude it is fine, and be completely wrong about what a Windows user's agent receives when it follows the same link." Because the malicious behavior only appears at request time and only to certain visitors, static review tools that check source files rather than live responses have no way to catch it — a gap that matters more as agentic tools increasingly act on links found in documentation without a human double-checking first.
A pattern, not a one-off
Manifold says it has since identified 13 more placeholder-style domains — names like yoursite[.]com and your-domain[.]com that sound like they belong to no one in particular but were never reserved. Two of them serve an ordinary parking page to most visitors but switch to scam content for macOS users. Security researcher Cody Nash described your-domain[.]com presenting a fake "MacOS Security Center" warning of four viruses and offering a counterfeit McAfee renewal at 55% off, while yoursite[.]com displayed a fabricated ZDF news article promoting an investment scheme.
What to ask your team
Budget-holders should ask three things: whether documentation, internal wikis, and AI agent skill or MCP-server configurations have been searched for non-reserved placeholder domains — not just third-party[.]com but lookalikes such as yourcompany[.]com or your-api[.]com; whether static code-scanning tools in use can even detect this class of issue, given that the malicious behavior only appears in a live browser response, not the source file; and whether any internal AI agents or automation are configured to follow links found in scanned documentation without a live-request check first.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Hacker News.





