Security
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The Hacker News·September 24, 2026·1 min read
The 'third-party[.]com' domain, a common documentation placeholder, now serves a ClickFix lure to Windows browsers while showing a harmless decoy to others. Manifold Security's Ax Sharma noted it has been a generic placeholder for years, unlike 'example[.]com,' and is referenced across 1,700+ repositories, posing a supply-chain risk.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
![Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy4aXDWSC5cKzOZO8lRbk8o5I1fHPlCGbfxxYL6tyJxauEL-8EVj7-AypDhYt_Wg6bDLqlj0UK4LrGJdeI4ChsksaB6tTZxo8ikCLdwC0wjRfJPE_Z1qM_CVUg7s1ORdmWW2XTDtlPPDcI8JvelrbmJhcjVthnqYWQrZ7ySnIMMPRZfa_VzgaBCWyWc_JJ/s1600/third.jpg)