![Placeholder Domain third-party[.]com Observed Serving ClickFix Lure to Windows Browsers](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy4aXDWSC5cKzOZO8lRbk8o5I1fHPlCGbfxxYL6tyJxauEL-8EVj7-AypDhYt_Wg6bDLqlj0UK4LrGJdeI4ChsksaB6tTZxo8ikCLdwC0wjRfJPE_Z1qM_CVUg7s1ORdmWW2XTDtlPPDcI8JvelrbmJhcjVthnqYWQrZ7ySnIMMPRZfa_VzgaBCWyWc_JJ/s1700-nu-rw-lo-l85-e365/third.jpg)
Placeholder Domain third-party[.]com Observed Serving ClickFix Lure to Windows Browsers
Manifold Security researcher Ax Sharma has reported that the domain third-party[.]com, frequently used as a generic documentation placeholder across software projects, is being exploited by threat actors. The domain serves a ClickFix social engineering lure specifically to Windows browser users, while displaying a harmless decoy to other visitors. The domain's widespread use in approximately 1,700+ repositories has increased the likelihood of encounter by developers and researchers. No software patch is available for the domain itself; mitigation focuses on user awareness of ClickFix tactics.




