Placeholder domain third-party.com hijacked to serve ClickFix malware attacks

Fake Cloudflare CAPTCHA tricks Windows users into running malicious PowerShell commands

By LineZotpaper
Published
Read Time3 min
The domain third-party.com, a long-standing placeholder in developer documentation and code examples, is now serving a fake Cloudflare verification page that attempts to trick Windows users into executing malicious PowerShell commands, security researchers reported.

The "third-party.com" domain, commonly used in documentation to represent an arbitrary external website, API, or service, has been observed hosting a ClickFix attack that impersonates a Cloudflare security check.

Unlike example.com, example.net, and example.org — which IANA reserves specifically for documentation — third-party.com is a normally registered domain whose content its owner can control. That distinction has become a security concern after the domain began serving the malicious page.

Manifold Security first reported the abuse after discovering it while examining public AI skills and MCP server documentation that referenced the domain. BleepingComputer confirmed that the page displays a fake Cloudflare "Performing security verification" CAPTCHA screen containing a "Verify you are human" prompt. When a visitor clicks the verification box, the site copies a malicious PowerShell command to the Windows clipboard and instructs the user to press Windows key + R, paste the contents using Ctrl+V, and press Enter.

If run, the PowerShell command reconstructs the payload URL elxxvvx[.]xyz/f, downloads a PowerShell script from that address, and executes it. The technique, known as ClickFix, uses fake errors, CAPTCHA prompts, or verification pages to convince victims to run commands themselves — a method that can bypass traditional antivirus software because the malware is installed via commands executed by the user rather than downloaded from a website or email attachment.

At the time of BleepingComputer's testing, elxxvvx[.]xyz no longer resolved, leaving the current attack chain broken. However, a Hybrid Analysis report from May 2, 2026, shows the site previously distributed a PowerShell script configured to download a 134MB zip archive from elxxvvx[.]xyz/update2.zip. The script saved the archive as update26.zip, extracted it, and attempted to launch an executable named draw.io.exe. Because the update2.zip archive is no longer available, researchers could not determine what the payload does.

The attack specifically targets Windows users, according to Manifold's Ax Sharma. "A macOS or Linux user-agent gets none of that. It gets a near-identical page that stops at an error: 'macOS is not supported. This website requires a Windows PC to access.' No clipboard poisoning, no payload," Sharma explained. "The attacker only shows the weapon to the targets it works against, which is precisely why a casual look, or a scanner on a Linux datacenter IP, sees nothing wrong."

§

Analysis

Why This Matters

  • Developers and users who follow documentation referencing third-party.com could be directed to a malicious page disguised as a routine security check, with no warning that the domain is no longer safe.
  • Placeholder domains are widely trusted as inert examples; this attack shows registered placeholder domains can be weaponized, undermining a common convention in technical writing.
  • The attack's selective targeting of Windows users means conventional security scanners running on Linux systems may see nothing suspicious, allowing the threat to go unnoticed.

Background

Placeholder domains like third-party.com have been used for decades in code samples, API documentation, and configuration examples to represent arbitrary external services. Unlike IANA-reserved example domains, registered placeholder domains remain under the control of their owners and can be redirected or repurposed at any time. ClickFix attacks have become an increasingly popular malware distribution technique, using fake CAPTCHAs and error messages to trick users into manually executing commands copied to their clipboard.

Key Perspectives

Documentation maintainers and developers: Those who reference third-party.com in guides and sample code may inadvertently expose readers to a malicious page; the incident highlights the value of using IANA-reserved example domains instead. Manifold Security and researchers: The attacker's decision to only serve the payload to Windows targets shows a deliberate effort to evade detection by security tools, making manual verification of referenced domains more important. Critics/Skeptics: The current attack chain is broken because the payload domain no longer resolves, and the actual malware's behavior remains unknown since the zip archive is unavailable. The practical risk at this moment is limited to users who visit the page and follow the instructions.

What to Watch

  • Whether elxxvvx[.]xyz resolves again or a new payload domain appears, indicating the campaign has resumed.
  • Whether the owner of third-party.com cleans up the malicious page or the domain continues serving malware.
  • Whether security researchers and documentation projects begin auditing other registered placeholder domains for similar abuse.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.