{"id":2018,"date":"2026-09-28T11:19:36","date_gmt":"2026-09-28T05:49:36","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2018"},"modified":"2026-09-30T10:00:33","modified_gmt":"2026-09-30T04:30:33","slug":"third-party-com-malware-placeholder-domain-fuels-clickfix-attack","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/","title":{"rendered":"third-party.com Malware: Placeholder Domain Fuels ClickFix Attack"},"content":{"rendered":"<p>Developers have treated third-party.com as a safe stand-in for years, much like example.com. Manifold Security found that someone registered the domain. It now serves third-party.com malware to Windows visitors through a ClickFix lure.<\/p>\n<p>The domain sat outside IANA&#8217;s reserved list, so anyone could claim it, and someone did. Every repository, AI skill, or MCP-server doc that hard-coded it now points to attacker infrastructure. The victim needed no code change for this to happen.<\/p>\n<p>This points to a wider placeholder domain abuse problem. Static review cannot catch a link that behaves differently depending on the visitor&#8217;s operating system.<\/p>\n<h2>How a placeholder domain became live infrastructure<\/h2>\n<p>Manifold Security&#8217;s Ax Sharma explained the core problem plainly: third-party.com looked exactly like example.com, but nothing protected it from registration. IANA reserves example.com, example.org, and example.net for this purpose. third-party.com carries no such protection.<\/p>\n<p>That gap turned a harmless convention into a supply-chain-style exposure:<\/p>\n<ul>\n<li>Thousands of developers copied third-party.com into docs, tests, and AI agent skills, treating it as inert.<\/li>\n<li>An unrelated party registered the domain and configured it to serve conditional, malicious content.<\/li>\n<li>Every existing reference became a live pointer to attacker infrastructure, with no update needed on the attacker&#8217;s end.<\/li>\n<\/ul>\n<p>Sharma noted that scanning the code alone would not reveal the problem. A file scan cannot see what a website decides to send at request time.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-essentials.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity essentials for any organization<\/h4><p>Cybersecurity essentials every organization needs, plus how Hexnode UEM helps.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-essentials-for-any-organization\/\" aria-label=\"Cybersecurity essentials for any organization\"><\/a><\/div><\/div><\/div>\n<h2>Inside the ClickFix PowerShell attack<\/h2>\n<p>The domain now runs a ClickFix PowerShell attack. This <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-social-engineering\/\">social engineering<\/a> technique uses a fake browser prompt to trick users into running <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malicious-code\/\">malicious code<\/a>.<\/p>\n<h3>Here&#8217;s how it plays out for Windows users:<\/h3>\n<ul>\n<li>A fake Cloudflare verification check appears on screen.<\/li>\n<li>The page silently copies a command to the clipboard, known as clipboard poisoning or pastejacking.<\/li>\n<li>The lure instructs the victim to manually open the Windows Run dialog (Win + R). It tells them to paste the clipboard contents (Ctrl + V) and press Enter.<\/li>\n<li>The command fetches and runs a remote PowerShell payload.<\/li>\n<\/ul>\n<p>macOS visitors to third-party.com see something different. The page shows a decoy error claiming macOS is not supported and that the visitor needs a Windows PC. This decoy keeps the campaign focused on Windows targets on this domain and avoids raising suspicion elsewhere. Manifold reported this behavior has run since at least June 2026.<\/p>\n<p>macOS is not exempt from this campaign model, though. Other non-reserved domains, like yoursite.com and your-domain.com, actively serve macOS visitors scareware and scam content, detailed below.<\/p>\n<h2>The Blast radius: MCP servers and AI agent skills<\/h2>\n<p>A GitHub search turned up more than 1,700 public repositories referencing third-party.com. Some directly touch <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-agentic-ai-security\/\">AI agent security<\/a> and MCP server risk:<\/p>\n<ul>\n<li>AI agent skills that cite the domain as a sample endpoint in tool definitions.<\/li>\n<li>MCP-server documentation that uses it as a placeholder API target.<\/li>\n<li>General developer documentation, test fixtures, and example configs across unrelated projects.<\/li>\n<\/ul>\n<p>This developer documentation security problem carries extra weight for AI agents. An agent resolving a link at runtime gets the same malicious content a browser gets. It misses the visual cues a person might notice.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download this cybersecurity kit with blueprints, framework guides, checklists, policy templates, and useful UEM guides.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>13 more placeholder domains at risk<\/h2>\n<p>Manifold&#8217;s research did not stop at one domain. The team identified 13 more non-reserved, placeholder-style domains, including your-domain.com, yourdomain.com, mycompany.com, and company.com. Two of them, yoursite.com and your-domain.com, serve scareware and a fake investment-scheme article to macOS visitors. Everyone else sees an ordinary parking page.<\/p>\n<p>Researcher Cody Nash noted these two domains alone appear in hundreds of thousands of GitHub files. They also turn up in hundreds of agent skills, a far larger exposure than the initial finding.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align: left;\"><strong>Placeholder Domain Behavior<\/strong><\/th>\n<th style=\"text-align: left;\"><strong>What Visitors See<\/strong><\/th>\n<th style=\"text-align: left;\"><strong>Operational Priority<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>third-party.com (Windows)<\/td>\n<td>Fake Cloudflare check, clipboard poisoning, PowerShell payload<\/td>\n<td>High: active code execution risk<\/td>\n<\/tr>\n<tr>\n<td>third-party.com (macOS)<\/td>\n<td>Decoy &#8220;unsupported OS&#8221; error<\/td>\n<td>Low: no payload delivered<\/td>\n<\/tr>\n<tr>\n<td>yoursite.com \/ your-domain.com (macOS)<\/td>\n<td>Fake security alert, scareware, investment scam<\/td>\n<td>Medium: fraud and credential exposure<\/td>\n<\/tr>\n<tr>\n<td>yoursite.com \/ your-domain.com (other)<\/td>\n<td>Ordinary parking page<\/td>\n<td>Low: currently inert<\/td>\n<\/tr>\n<tr>\n<td>Remaining 11 domains<\/td>\n<td>Not yet reported as actively malicious<\/td>\n<td>Medium: squattable, needs monitoring<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Where Hexnode fits<\/h2>\n<p>Hexnode cannot detect the third-party.com domain itself or patch the sites that host it. Domain takedowns and reputation blocks still handle that layer. Hexnode reduces the chance that a ClickFix-style command runs successfully on managed endpoints. Here&#8217;s how each product contributes:<\/p>\n<h3>Hexnode XDR<\/h3>\n<ul>\n<li>Protects managed Windows and macOS endpoints today.<\/li>\n<li>Tracks process execution telemetry, including parent-child chains. This can surface a browser binary (chrome.exe) spawning a command shell (cmd.exe) or scripting engine (powershell.exe).<\/li>\n<li>Let admins review these chains from the <a href=\"https:\/\/www.hexnode.com\/xdr\/\">XDR<\/a> Incidents dashboard as part of ongoing investigation.<\/li>\n<li>Hexnode XDR enables immediate incident containment. Security teams can terminate malicious processes or isolate compromised endpoints directly from the XDR dashboard.<\/li>\n<\/ul>\n<h3>Hexnode UEM<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/\">UEM<\/a>\u00a0supports application blocklisting and execution controls across Windows, macOS, and Linux endpoints.<\/li>\n<li>Lets teams block scripting engines like PowerShell and cmd.exe through application blocklisting. This stops unauthenticated scripting engines from executing unprompted on developer machines.<\/li>\n<li>Teams can push a custom script through Hexnode UEM&#8217;s Execute Custom Script action. This can set PowerShell execution policy, apply Constrained Language Mode, or restrict Run dialog and command-line access via registry changes.<\/li>\n<\/ul>\n<p>Neither capability replaces auditing internal documentation or rotating exposed API keys and tokens. Hexnode complements that work at the endpoint layer.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can our team find out if we reference third-party.com or similar placeholder domains?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Search your repositories, docs, and AI agent skill definitions for the exact string. GitHub&#8217;s code search can help you find these matches directly.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does this risk apply to AI agents that read documentation automatically, not just humans clicking links?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. An agent that resolves a link at runtime can receive the same conditional, malicious content a human browser would get.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should we use instead of third-party.com in code and documentation examples?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Use IANA-reserved domains only, such as example.com, example.org, or example.net. No one else can register these.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n<h3>Conclusion<\/h3>\n<p>A domain that looked like harmless boilerplate is now an active third-party.com malware delivery path for Windows users. The lesson extends past this one domain. Any unreserved, plausible-sounding placeholder in code, docs, or AI agent skills carries the same squatting risk.<\/p>\n<p>Security teams should audit documentation and AI tooling for non-reserved placeholder domains now. Standardize on reserved alternatives going forward. Pair that audit with endpoint controls that limit what a pasted command can do.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay ahead of the next placeholder trap <\/h5><p>Get threat intelligence like this delivered before it reaches your endpoints. <\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Developers have treated third-party.com as a safe stand-in for years, much like example.com. Manifold Security&#8230;<\/p>\n","protected":false},"author":5,"featured_media":2033,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14,16],"class_list":["post-2018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-supply-chain-attack","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>third-party.com Malware Turns Docs Into a ClickFix Trap<\/title>\n<meta name=\"description\" content=\"third-party.com malware delivers ClickFix PowerShell attacks through a placeholder domain cited in 1,700+ GitHub repos and AI agent skills.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"third-party.com Malware Turns Docs Into a ClickFix Trap\" \/>\n<meta property=\"og:description\" content=\"third-party.com malware delivers ClickFix PowerShell attacks through a placeholder domain cited in 1,700+ GitHub repos and AI agent skills.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-28T05:49:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T04:30:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/third-party.com-malware.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"third-party.com Malware: Placeholder Domain Fuels ClickFix Attack\",\"datePublished\":\"2026-09-28T05:49:36+00:00\",\"dateModified\":\"2026-09-30T04:30:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/\"},\"wordCount\":1156,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/third-party.com-malware.jpeg?format=webp\",\"articleSection\":[\"Supply Chain Attack\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/\",\"name\":\"third-party.com Malware Turns Docs Into a ClickFix Trap\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/third-party.com-malware.jpeg?format=webp\",\"datePublished\":\"2026-09-28T05:49:36+00:00\",\"dateModified\":\"2026-09-30T04:30:33+00:00\",\"description\":\"third-party.com malware delivers ClickFix PowerShell attacks through a placeholder domain cited in 1,700+ GitHub repos and AI agent skills.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/third-party.com-malware.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/third-party.com-malware.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"third-party.com malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"third-party.com Malware: Placeholder Domain Fuels ClickFix Attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"third-party.com Malware Turns Docs Into a ClickFix Trap","description":"third-party.com malware delivers ClickFix PowerShell attacks through a placeholder domain cited in 1,700+ GitHub repos and AI agent skills.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/","og_locale":"en_US","og_type":"article","og_title":"third-party.com Malware Turns Docs Into a ClickFix Trap","og_description":"third-party.com malware delivers ClickFix PowerShell attacks through a placeholder domain cited in 1,700+ GitHub repos and AI agent skills.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-28T05:49:36+00:00","article_modified_time":"2026-09-30T04:30:33+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/third-party.com-malware.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"third-party.com Malware: Placeholder Domain Fuels ClickFix Attack","datePublished":"2026-09-28T05:49:36+00:00","dateModified":"2026-09-30T04:30:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/"},"wordCount":1156,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/third-party.com-malware.jpeg?format=webp","articleSection":["Supply Chain Attack","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/","url":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/","name":"third-party.com Malware Turns Docs Into a ClickFix Trap","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/third-party.com-malware.jpeg?format=webp","datePublished":"2026-09-28T05:49:36+00:00","dateModified":"2026-09-30T04:30:33+00:00","description":"third-party.com malware delivers ClickFix PowerShell attacks through a placeholder domain cited in 1,700+ GitHub repos and AI agent skills.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/third-party.com-malware.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/third-party.com-malware.jpeg?format=webp","width":1340,"height":700,"caption":"third-party.com malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/third-party-com-malware-placeholder-domain-fuels-clickfix-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"third-party.com Malware: Placeholder Domain Fuels ClickFix Attack"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2018"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2018\/revisions"}],"predecessor-version":[{"id":2090,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2018\/revisions\/2090"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2033"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}