Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

Summary

The domain "third-party[.]com," historically used as a documentation placeholder, has been found to serve malicious content. Specifically, it displays a ClickFix lure to Windows browsers while presenting harmless decoy content to other users.

IFF Assessment

FOE

This discovery is bad news for defenders as a commonly trusted placeholder domain has been weaponized to deliver malicious lures.

Defender Context

Defenders should be aware that even seemingly innocuous and commonly used domains can be compromised and used for malicious purposes. This highlights the importance of scrutinizing all external resources, especially those embedded or referenced in documentation, and implementing robust web filtering and endpoint protection to detect and block such lures.

Read Full Story →