Placeholder domain third-party.com now serves ClickFix attacks
The third-party.com domain, long used as a placeholder in developer documentation, now displays a fake Cloudflare verification page. It copies a malicious PowerShell command to the clipboard that victims are tricked into running manually.
- Fake Cloudflare CAPTCHA copies a PowerShell command to the clipboard
- ClickFix attack targets only Windows; macOS and Linux see an error
- Domain appears in 1,500+ files across 1,700+ repos, including Chromium and Vercel
- Domain registered in 1996; malicious page live since at least June 2026
Read next
Security