Back to all news
Security

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The Hacker News·September 24, 2026·1 min read
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The 'third-party[.]com' domain, a common documentation placeholder, now serves a ClickFix lure to Windows browsers while showing a harmless decoy to others. Manifold Security's Ax Sharma noted it has been a generic placeholder for years, unlike 'example[.]com,' and is referenced across 1,700+ repositories, posing a supply-chain risk.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store