A domain name that developers have treated like a harmless placeholder for years is now being used to deliver a ClickFix attack.
According to BleepingComputer, third-party.com has appeared in developer documentation and code examples as a stand-in for an outside website, service, or application. References have appeared in material associated with projects including Chromium and World Wide Web Consortium specifications.
There is one rather significant problem: third-party.com isn’t actually a reserved example domain.
It is a real, registered domain, and the person or organization controlling it can decide what visitors receive.
Right now, visitors may receive a fake Cloudflare verification page designed to convince Windows users to run a malicious PowerShell command.
What is ClickFix?
ClickFix is a social-engineering technique in which an attacker presents something such as a fake error message, CAPTCHA, security check, or verification procedure and gives the victim instructions supposedly needed to fix the problem.
Rather than exploiting a software vulnerability directly, the attacker tries to convince the victim to perform the dangerous action.
In the attack observed at third-party.com, BleepingComputer reports that clicking the fake verification box causes a malicious PowerShell command to be placed on the Windows clipboard. The page then instructs the victim to open the Windows Run dialog, paste what is on the clipboard, and execute it.
If followed, those instructions cause Windows to retrieve and execute additional malicious code.
Third-party.com is not example.com
This is where the story becomes particularly interesting.
There are domain names specifically reserved for examples and documentation.
The Internet Assigned Numbers Authority, better known as IANA, maintains domains including example.com, example.net, and example.org for precisely this purpose. These domains can be used as illustrative examples in documentation and are not available for registration or transfer.
That means an author can safely write something such as example.com into documentation without worrying that somebody will later purchase the domain and turn it into something malicious.
Third-party.com doesn’t have that protection.
It may sound like generic placeholder text, but it is an ordinary registered domain.
Think about a domain such as MENVI.org. That is a real Internet property controlled by its registrant. Its owner can operate a website, configure email, change where the domain points, or make other changes to services associated with it.
Third-party.com is similarly a real domain rather than a permanently reserved example.
That distinction becomes extremely important when developers put a domain into documentation or, worse, executable example code that might actually contact it.
Who are IANA and ICANN?
Several organizations are involved in keeping Internet names and numbers coordinated, and their names can become confusing.
IANA, the Internet Assigned Numbers Authority, maintains authoritative registries for globally coordinated Internet identifiers. Its responsibilities broadly include domain names, Internet number resources, and protocol parameters. The IANA functions are performed by Public Technical Identifiers, an affiliate of ICANN.
ICANN, the Internet Corporation for Assigned Names and Numbers, is a nonprofit public-benefit organization that coordinates the Internet’s unique identifier systems. Among other responsibilities, it coordinates aspects of the Domain Name System, or DNS, and works with domain registries and accredited registrars.
DNS is the system that allows people to use names such as example.com instead of having to remember the numerical IP addresses computers use to locate one another.
And what is ARIN?
Another organization people sometimes encounter while investigating Internet infrastructure is ARIN, the American Registry for Internet Numbers.
ARIN is somewhat different because its primary responsibility isn’t registering ordinary domain names.
ARIN is one of the world’s Regional Internet Registries. It manages and distributes Internet number resources, including IPv4 addresses, IPv6 addresses, and Autonomous System Numbers, or ASNs, within its service region.
In practical security research, ARIN can therefore be useful when investigating who has been assigned an IP address or block of addresses, while domain-registration information is obtained through the appropriate domain-registration services. ARIN specifically notes that ordinary domain-name registration information is not part of its authoritative registry data.
A domain dating back to 1996
The age of third-party.com makes this situation even more unusual.
The ICANN registration information examined for this article shows that third-party.com was originally created in 1996. The current registration record has an update date in 2026 and an expiration date in 2031.
The 2026 update date should not automatically be interpreted as the date the domain changed ownership or was renewed. Registration records can be updated for numerous reasons, so the date by itself doesn’t establish what changed.
BleepingComputer similarly reports that the domain was first registered in 1996 and says there is no evidence that it was originally registered for malicious purposes. The publication could not determine when or how control of the site changed.
That distinction matters. This is not a newly registered domain that appeared solely for this ClickFix campaign. It has existed for roughly three decades.
Years of examples create an unusual problem
According to BleepingComputer, researchers found references to third-party.com in more than 1,500 files across more than 1,700 repositories. Examples have appeared in documentation associated with recognizable projects and organizations.
Some examples aren’t merely text for a reader to look at. Code copied literally could make an actual network request to third-party.com.
That doesn’t mean those projects or their documentation have been compromised.
It means something more subtle happened: developers used a real domain as though it were inert placeholder text. Years later, the behavior of that domain changed.
A developer copying old example code today could therefore contact a real website that behaves very differently from whatever the documentation’s original author imagined.
BleepingComputer says there have not been reports showing that these existing references have actually caused ClickFix attacks to execute on developers’ systems or inside applications. That is an important limitation to keep in mind.
The larger lesson
The lesson here extends beyond third-party.com.
If documentation requires a fictitious Internet domain, use a domain specifically reserved for that purpose.
Something that merely looks generic isn’t necessarily harmless.
example.com, example.net, and example.org were designed for examples and cannot simply be purchased by someone who decides years later to serve malicious content from them.
An ordinary registered domain has no such guarantee.
Third-party.com demonstrates why that distinction matters. A name that looked harmless enough to become embedded throughout years of developer documentation now points visitors toward a ClickFix attack.
Thirty years after the domain was first registered, that old assumption has become a security problem nobody writing those examples may have anticipated.
Sources
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Placeholder domain used in dev docs now serves ClickFix attacks
A domain name that developers have treated like a harmless placeholder for years is now being used to deliver a ClickFix attack.
According to BleepingComputer, third-party.com has appeared in developer documentation and code examples as a stand-in for an outside website, service, or application. References have appeared in material associated with projects including Chromium and World Wide Web Consortium specifications.
There is one rather significant problem: third-party.com isn’t actually a reserved example domain.
It is a real, registered domain, and the person or organization controlling it can decide what visitors receive.
Right now, visitors may receive a fake Cloudflare verification page designed to convince Windows users to run a malicious PowerShell command.
What is ClickFix?
ClickFix is a social-engineering technique in which an attacker presents something such as a fake error message, CAPTCHA, security check, or verification procedure and gives the victim instructions supposedly needed to fix the problem.
Rather than exploiting a software vulnerability directly, the attacker tries to convince the victim to perform the dangerous action.
In the attack observed at third-party.com, BleepingComputer reports that clicking the fake verification box causes a malicious PowerShell command to be placed on the Windows clipboard. The page then instructs the victim to open the Windows Run dialog, paste what is on the clipboard, and execute it.
If followed, those instructions cause Windows to retrieve and execute additional malicious code.
Third-party.com is not example.com
This is where the story becomes particularly interesting.
There are domain names specifically reserved for examples and documentation.
The Internet Assigned Numbers Authority, better known as IANA, maintains domains including example.com, example.net, and example.org for precisely this purpose. These domains can be used as illustrative examples in documentation and are not available for registration or transfer.
That means an author can safely write something such as example.com into documentation without worrying that somebody will later purchase the domain and turn it into something malicious.
Third-party.com doesn’t have that protection.
It may sound like generic placeholder text, but it is an ordinary registered domain.
Think about a domain such as MENVI.org. That is a real Internet property controlled by its registrant. Its owner can operate a website, configure email, change where the domain points, or make other changes to services associated with it.
Third-party.com is similarly a real domain rather than a permanently reserved example.
That distinction becomes extremely important when developers put a domain into documentation or, worse, executable example code that might actually contact it.
Who are IANA and ICANN?
Several organizations are involved in keeping Internet names and numbers coordinated, and their names can become confusing.
IANA, the Internet Assigned Numbers Authority, maintains authoritative registries for globally coordinated Internet identifiers. Its responsibilities broadly include domain names, Internet number resources, and protocol parameters. The IANA functions are performed by Public Technical Identifiers, an affiliate of ICANN.
ICANN, the Internet Corporation for Assigned Names and Numbers, is a nonprofit public-benefit organization that coordinates the Internet’s unique identifier systems. Among other responsibilities, it coordinates aspects of the Domain Name System, or DNS, and works with domain registries and accredited registrars.
DNS is the system that allows people to use names such as example.com instead of having to remember the numerical IP addresses computers use to locate one another.
And what is ARIN?
Another organization people sometimes encounter while investigating Internet infrastructure is ARIN, the American Registry for Internet Numbers.
ARIN is somewhat different because its primary responsibility isn’t registering ordinary domain names.
ARIN is one of the world’s Regional Internet Registries. It manages and distributes Internet number resources, including IPv4 addresses, IPv6 addresses, and Autonomous System Numbers, or ASNs, within its service region.
In practical security research, ARIN can therefore be useful when investigating who has been assigned an IP address or block of addresses, while domain-registration information is obtained through the appropriate domain-registration services. ARIN specifically notes that ordinary domain-name registration information is not part of its authoritative registry data.
A domain dating back to 1996
The age of third-party.com makes this situation even more unusual.
The ICANN registration information examined for this article shows that third-party.com was originally created in 1996. The current registration record has an update date in 2026 and an expiration date in 2031.
The 2026 update date should not automatically be interpreted as the date the domain changed ownership or was renewed. Registration records can be updated for numerous reasons, so the date by itself doesn’t establish what changed.
BleepingComputer similarly reports that the domain was first registered in 1996 and says there is no evidence that it was originally registered for malicious purposes. The publication could not determine when or how control of the site changed.
That distinction matters. This is not a newly registered domain that appeared solely for this ClickFix campaign. It has existed for roughly three decades.
Years of examples create an unusual problem
According to BleepingComputer, researchers found references to third-party.com in more than 1,500 files across more than 1,700 repositories. Examples have appeared in documentation associated with recognizable projects and organizations.
Some examples aren’t merely text for a reader to look at. Code copied literally could make an actual network request to third-party.com.
That doesn’t mean those projects or their documentation have been compromised.
It means something more subtle happened: developers used a real domain as though it were inert placeholder text. Years later, the behavior of that domain changed.
A developer copying old example code today could therefore contact a real website that behaves very differently from whatever the documentation’s original author imagined.
BleepingComputer says there have not been reports showing that these existing references have actually caused ClickFix attacks to execute on developers’ systems or inside applications. That is an important limitation to keep in mind.
The larger lesson
The lesson here extends beyond third-party.com.
If documentation requires a fictitious Internet domain, use a domain specifically reserved for that purpose.
Something that merely looks generic isn’t necessarily harmless.
example.com, example.net, and example.org were designed for examples and cannot simply be purchased by someone who decides years later to serve malicious content from them.
An ordinary registered domain has no such guarantee.
Third-party.com demonstrates why that distinction matters. A name that looked harmless enough to become embedded throughout years of developer documentation now points visitors toward a ClickFix attack.
Thirty years after the domain was first registered, that old assumption has become a security problem nobody writing those examples may have anticipated.
Sources
Share this:
Like this:
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Published in article commentary