A domain that developers have always treated as a stand-in is now an attack path. third-party[.]com, the placeholder teams drop into documentation and test code whenever an outside vendor needs naming, has been serving a ClickFix lure since at least June 2026, according to Manifold Security.
The difference from example.com is ownership. IANA reserves example.com, so nobody may register it; third-party[.]com carried no such protection, and someone bought it. Windows visitors now land on a fake Cloudflare human check, and that page quietly fills the clipboard, then tells the reader to paste the planted line into the Run dialog, where it retrieves and executes a remote PowerShell payload. Mac users are turned away with a notice that the site needs a Windows PC.
Trusted by default, malicious in practice
Scale is what turns one squatted domain into an industry problem. A GitHub search finds the address inside more than 1,700 public repositories, among them documentation for AI agent skills and MCP servers that hold it up as an example endpoint. None of those authors did anything wrong when they wrote it down. Today their references resolve to attacker infrastructure, which also creates an opening for prompt injection and other unintended behavior.
third-party[.]com has been reported to VirusTotal, Google Safe Browsing and its registrar, but the durable fix is a habit rather than a takedown. Audit your documentation for plausible non-reserved placeholders and standardize on example.com, example.org or example.net instead. ClickFix traffic is climbing fast; one vendor has measured a 108 percent jump in detections.
