Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
- ID
- 28183
- Status
- summarized
- Published
- 24 Sep 2026, 11:27 PM
- Fetched
- 25 Sep 2026, 12:40 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 25 Sep 2026, 12:41 AM
- Tags
- Audience
- developersvibe_codersai_agent_usersai_ml_learners
What happened
The Hacker News reports that third-party[.]com, a long-standing documentation placeholder that is not IANA-reserved, was registered by someone and has been serving a ClickFix lure to Windows browsers since at least June 2026. Windows visitors get a fake Cloudflare check that poisons the clipboard and instructs them to paste a command into the Run dialog, which pulls and executes a remote PowerShell payload; macOS visitors just see an error saying a Windows PC is required. A GitHub search shows the domain is referenced in over 1,700 public repositories, including AI agent skill docs and MCP-server docs that cite it as an example endpoint, and it is now flagged on VirusTotal and Google Safe Browsing.
Why it matters
Anyone who wrote third-party[.]com into a README, test fixture, or MCP/agent-skill example endpoint now ships a live link to attacker infrastructure — and the payload only fires when a human pastes into the Windows Run dialog, so automated CI won't catch it. Grep your repos and internal docs for that hostname this week and replace it with an IANA-reserved placeholder (example.com) or a domain you control; if you maintain MCP server docs or agent tool configs that list example endpoints, audit them first, because agents and their users follow those examples literally.
Discussion angle
Docs and agent configs treat example URLs as inert text, but this shows they are live, registerable infrastructure — should MCP server docs and agent skill templates be required to use only IANA-reserved domains, and should agents ever be allowed to fetch endpoints copied verbatim from a README?