Placeholder domain third-party.com becomes ClickFix malware host

Attackers are using third-party[.]com, a domain often used as a placeholder in documentation, to deliver malware. The site serves a ClickFix lure that imitates a Cloudflare check, poisons the clipboard, and instructs users to run a PowerShell payload via Win+R. Manifold Security found the issue and reported the domain to its registrar, but the threat remains.
The domain third-party[.]com is not protected like example.com, example.org, and similar names set aside by IANA, so it was available for registration. Manifold Security found it serving a ClickFix lure that fakes a Cloudflare human-verification prompt, alters the clipboard, and directs victims to open Run and paste a command. That command retrieves and executes a remote PowerShell payload.
ClickFix has circulated for roughly two years with different lures. ESET reported detections increased 108% from the second half of 2025 to the first half of 2026, after a 517% rise in its prior report. Manifold alerted Network Solutions, the registrar, yet the site reportedly remains live.
This incident could affect developers, IT teams, and ordinary users who encounter third-party[.]com in copied examples or documentation. Because the domain looks like a harmless placeholder, employees or customers may visit it without suspicion, potentially enabling malware execution on Windows systems. Enterprises may face cleanup costs, disrupted work, and data exposure if such lures succeed. The continued availability of the site may also erode trust in common documentation practices, though the actual harm depends on whether users follow the clipboard instructions.