Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
Summary
The domain "third-party[.]com," historically used as a documentation placeholder, has been found to serve malicious content. Specifically, it displays a ClickFix lure to Windows browsers while presenting harmless decoy content to other users.
IFF Assessment
FOE
This discovery is bad news for defenders as a commonly trusted placeholder domain has been weaponized to deliver malicious lures.
Defender Context
Defenders should be aware that even seemingly innocuous and commonly used domains can be compromised and used for malicious purposes. This highlights the importance of scrutinizing all external resources, especially those embedded or referenced in documentation, and implementing robust web filtering and endpoint protection to detect and block such lures.