hacker-news · Crawled Sep 24, 2026

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

14 IoCs
Read original article ↗

AI Summary

The domain third-party[.]com, historically used as a documentation placeholder in code and technical writing, has been registered by an attacker and is now serving a ClickFix social engineering lure targeting Windows users. When accessed from Windows, the site poisons the clipboard with a malicious PowerShell command intended for execution via the Run dialog, while showing a benign or unsupported message to other platforms like macOS. The domain is referenced in over 1,700 public GitHub repositories, including AI agent skills and API documentation, amplifying exposure. Additionally, two other placeholder domains—yoursite[.]com and your-domain[.]com—are actively serving scams and scareware, particularly targeting macOS users with fake security alerts and fraudulent investment offers.

AI-extracted · verify before operational use

Indicators of Compromise 14 extracted

Type Value Detail
Domain third-party[.]com Details →
Domain yoursite[.]com Details →
Domain your-domain[.]com Details →
Domain yourdomain[.]com Details →
Domain your-site[.]com Details →
Domain your-app[.]com Details →
Domain yourapp[.]com Details →
Domain myapp[.]com Details →
Domain mysite[.]com Details →
Domain acme[.]com Details →
Domain company[.]com Details →
Domain mycompany[.]com Details →
Domain vendor[.]com Details →
Domain foo[.]com Details →