Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
AI Summary
The domain third-party[.]com, historically used as a documentation placeholder in code and technical writing, has been registered by an attacker and is now serving a ClickFix social engineering lure targeting Windows users. When accessed from Windows, the site poisons the clipboard with a malicious PowerShell command intended for execution via the Run dialog, while showing a benign or unsupported message to other platforms like macOS. The domain is referenced in over 1,700 public GitHub repositories, including AI agent skills and API documentation, amplifying exposure. Additionally, two other placeholder domains—yoursite[.]com and your-domain[.]com—are actively serving scams and scareware, particularly targeting macOS users with fake security alerts and fraudulent investment offers.
AI-extracted · verify before operational use
Indicators of Compromise 14 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | third-party[.]com | Details → |
| Domain | yoursite[.]com | Details → |
| Domain | your-domain[.]com | Details → |
| Domain | yourdomain[.]com | Details → |
| Domain | your-site[.]com | Details → |
| Domain | your-app[.]com | Details → |
| Domain | yourapp[.]com | Details → |
| Domain | myapp[.]com | Details → |
| Domain | mysite[.]com | Details → |
| Domain | acme[.]com | Details → |
| Domain | company[.]com | Details → |
| Domain | mycompany[.]com | Details → |
| Domain | vendor[.]com | Details → |
| Domain | foo[.]com | Details → |