third-party.com Placeholder Domain Now Serves ClickFix
The domain third-party[.]com, historically used as a documentation placeholder similar to example.com, has been compromised and now serves ClickFix lures to Windows users while displaying harmless content to other operating systems. Since at least June 2026, Windows visitors receive a fake Cloudflare verification page that poisons the clipboard with a malicious PowerShell command, instructing users to press Win+R and paste the payload. The domain appears in over 1,500 files across 1,700+ repositories from trusted sources including Chromium, Sanity, and Vercel. Unlike example.com, third-party[.]com is not IANA-reserved, allowing adversaries to register and weaponize it. The attack leverages social engineering to bypass security tools by using signed Windows binaries, making detection difficult through traditional scanning methods.
AI Analysis
Technical Summary
The third-party.com domain, used as a documentation placeholder similar to example.com, has been compromised and weaponized to deliver ClickFix malware lures to Windows users. Visitors on Windows are presented with a fake Cloudflare verification page that poisons their clipboard with a malicious PowerShell command, instructing them to execute it via the Run dialog (Win+R). This social engineering tactic leverages signed Windows binaries to bypass security detections. The domain is referenced in over 1,500 files across more than 1,700 repositories from trusted sources such as Chromium, Sanity, and Vercel, increasing the attack surface. Because third-party.com is not IANA-reserved, adversaries were able to register and exploit it. The campaign has been active since at least June 2026 and targets Windows users specifically, while showing benign content to other operating systems.
Potential Impact
Windows users visiting third-party.com are at risk of executing a malicious PowerShell payload due to clipboard poisoning and social engineering. The widespread use of the domain in trusted repositories increases the likelihood of exposure. The attack bypasses traditional security tools by using signed Windows binaries, making detection and prevention more challenging. There is no indication of active exploitation in the wild beyond this campaign, and no direct CVE or software vulnerability is involved.
Mitigation Recommendations
No official patch or fix is available as this is a social engineering campaign leveraging a compromised domain rather than a software vulnerability. Defenders should educate users to avoid executing clipboard-pasted commands from untrusted sources, especially when prompted by unexpected verification pages. Security teams should monitor for suspicious clipboard activity and PowerShell execution triggered by user input. Since the domain is not IANA-reserved, organizations should avoid using third-party.com as a placeholder domain in documentation or code to prevent accidental exposure. Traditional signature-based detection may be ineffective due to the use of signed binaries; behavioral detection and user awareness are critical.
Indicators of Compromise
- domain: elxxvvx.xyz
- url: http://elxxvvx.xyz/f
- url: http://elxxvvx.xyz/f'
- url: http://third-party.com/token
- url: http://third-party.com/widget.js
third-party.com Placeholder Domain Now Serves ClickFix
Description
The domain third-party[.]com, historically used as a documentation placeholder similar to example.com, has been compromised and now serves ClickFix lures to Windows users while displaying harmless content to other operating systems. Since at least June 2026, Windows visitors receive a fake Cloudflare verification page that poisons the clipboard with a malicious PowerShell command, instructing users to press Win+R and paste the payload. The domain appears in over 1,500 files across 1,700+ repositories from trusted sources including Chromium, Sanity, and Vercel. Unlike example.com, third-party[.]com is not IANA-reserved, allowing adversaries to register and weaponize it. The attack leverages social engineering to bypass security tools by using signed Windows binaries, making detection difficult through traditional scanning methods.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The third-party.com domain, used as a documentation placeholder similar to example.com, has been compromised and weaponized to deliver ClickFix malware lures to Windows users. Visitors on Windows are presented with a fake Cloudflare verification page that poisons their clipboard with a malicious PowerShell command, instructing them to execute it via the Run dialog (Win+R). This social engineering tactic leverages signed Windows binaries to bypass security detections. The domain is referenced in over 1,500 files across more than 1,700 repositories from trusted sources such as Chromium, Sanity, and Vercel, increasing the attack surface. Because third-party.com is not IANA-reserved, adversaries were able to register and exploit it. The campaign has been active since at least June 2026 and targets Windows users specifically, while showing benign content to other operating systems.
Potential Impact
Windows users visiting third-party.com are at risk of executing a malicious PowerShell payload due to clipboard poisoning and social engineering. The widespread use of the domain in trusted repositories increases the likelihood of exposure. The attack bypasses traditional security tools by using signed Windows binaries, making detection and prevention more challenging. There is no indication of active exploitation in the wild beyond this campaign, and no direct CVE or software vulnerability is involved.
Defensive Guidance
No official patch or fix is available as this is a social engineering campaign leveraging a compromised domain rather than a software vulnerability. Defenders should educate users to avoid executing clipboard-pasted commands from untrusted sources, especially when prompted by unexpected verification pages. Security teams should monitor for suspicious clipboard activity and PowerShell execution triggered by user input. Since the domain is not IANA-reserved, organizations should avoid using third-party.com as a placeholder domain in documentation or code to prevent accidental exposure. Traditional signature-based detection may be ineffective due to the use of signed binaries; behavioral detection and user awareness are critical.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.manifold.security/blog/third-party-com-placeholder-clickfix"]
- Pulse Id
- 6ab559662b978ca478cf0b21
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainelxxvvx.xyz | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://elxxvvx.xyz/f | — | |
urlhttp://elxxvvx.xyz/f' | — | |
urlhttp://third-party.com/token | — | |
urlhttp://third-party.com/widget.js | — |
Threat ID: 6ab581e9f7a7c54106c7b233
Added to database: 09/24/2026, 20:02:49 UTC
Last enriched: 09/24/2026, 20:17:52 UTC
Last updated: 09/25/2026, 01:47:34 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.