Cybersecurity

A Common Placeholder Domain in Developer Documentation Turns into a ClickFix Trap for Windows Users

The domain third-party.com, used for years as a default address in programming documentation and code examples, has begun displaying a fake Cloudflare page that pressures Windows users into executing malicious PowerShell commands. There are no confirmed reports that the attack succeeded, but the domain’s prevalence in public repositories and projects makes it a potential danger for code copied verbatim.

2026-09-23
4 min read
91 views
certi.news Editorial Team
A Common Placeholder Domain in Developer Documentation Turns into a ClickFix Trap for Windows Users

The domain third-party.com, which frequently appears in developer documentation and code examples as a default external website, has become a platform for a fake Cloudflare page using the ClickFix technique to target Windows users. Manifold Security discovered the malicious use while examining documentation related to artificial intelligence skills and MCP servers, and BleepingComputer then confirmed the page’s behavior.

The page displays a verification message titled “Performing security verification” and includes a “Verify you are human” box. After it is clicked, the page copies a malicious command to the Windows clipboard and asks the user to press Windows+R, then paste the command using Ctrl+V and run it. The command reconstructs a payload address from the domain elxxvvx[.]xyz, downloads PowerShell code, and runs it.

How Does the Trick Work?

ClickFix relies on persuading the victim to execute the command themselves instead of downloading a malicious file directly. According to an earlier analysis report dated May 2, 2026, the script attempted to download a 134-megabyte ZIP archive named update2.zip, save it locally as update26.zip, then extract it and run an executable named draw.io.exe. BleepingComputer was unable to identify the final payload because the archive was no longer available.

During testing, the domain elxxvvx[.]xyz no longer resolved to an active service, leaving the attack chain stalled at that time. However, the page distinguished between operating systems: Windows users saw the attack path, while macOS and Linux users received a message stating that the site required a Windows device. This selective targeting could conceal the behavior from checks that use Linux environments or data-center IP addresses.

Why Does the Choice of This Domain Matter?

The danger of the incident lies in the fact that third-party.com is not a domain reserved for documentation like example.com, example.net, and example.org; rather, it is a registered domain whose owner can control its content. Nevertheless, it has been used by W3C specifications, Chromium documentation, and other projects as a default address, and it appeared in more than 1,500 files across over 1,700 repositories, including repositories associated with names such as Chromium, Sanity, and Vercel.

If examples containing this address are copied into test code or an actual application, the browser or automated tool may connect to the real domain instead of treating it as a non-operational value, creating an opportunity to display malicious content. This does not mean that W3C, Chromium, or other projects have been compromised.

What Do We Know, and What Has Not Been Proven?

The source says that the domain has been registered since 1996, and there is no evidence that it was originally reserved for a malicious purpose. It is also not known when or how control of it changed. As of the time the report was prepared, there were no reports proving that ClickFix had actually been executed on developers’ devices or inside the applications and websites that reference the domain. However, the site’s continued availability means that attackers may later connect it to a new payload domain.

The practical lesson for developers and security teams is not to treat every test domain as safe merely because it appears in trusted documentation. Registrable addresses should be replaced with domains reserved for documentation, copied examples that make actual network requests should be reviewed, and users should be informed that legitimate verification pages do not usually ask them to open the Run window and manually paste PowerShell commands.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news