Act
active
Placeholder domain third-party[.]com now serves ClickFix malware via 1,700+ repos
- Engineer — Act: Search all repos, internal docs, and README files for references to ’third-party[.]com’ and replace them; any user clicking the link from documentation now risks a ClickFix social-engineering payload targeting Windows.
- SOC/IR — Act: Block third-party[.]com at DNS/proxy immediately, sweep web proxy and DNS logs for recent queries to that domain, and hunt for ClickFix execution indicators (mshta/PowerShell spawned from browser or Run dialog) since the domain became malicious.
- Leader — Plan: This demonstrates a new documentation-placeholder squatting attack class affecting thousands of open-source projects; task engineering to audit internal repos this quarter and add placeholder-domain checks to developer guidelines and repository scanning policy.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.