Skip to main content
CyberUnknownMedium
5.1

Placeholder domain 'third-party.com' hijacked to serve ClickFix malware

The domain 'third-party.com', widely used as a placeholder in dev docs, now hosts a fake Cloudflare check that prompts Windows users to run PowerShell, delivering ClickFix malware. This is a novel supply-chain style attack vector targeting developers and IT staff who copy-paste commands from documentation. The scale of exposure is uncertain but potentially broad given the domain's ubiquity in code examples.

BleepingComputer3 days agoUSengCredibility 22%View source

Score Breakdown

Mosaic Score5.1
Model confidence0.7
Significance0.5
Source credibility0.2

Intelligence Tags

Entities

countryconcept
Source

Related signals

8 found