CuraSec

Act active

Placeholder domain third-party[.]com now serves ClickFix malware via 1,700+ repos

2026-09-25 15:49 UTC · The Hacker News · read the source ↗ #clickfix#supply-chain#domain-hijacking
  • Engineer — Act: Search all repos, internal docs, and README files for references to ’third-party[.]com’ and replace them; any user clicking the link from documentation now risks a ClickFix social-engineering payload targeting Windows.
  • SOC/IR — Act: Block third-party[.]com at DNS/proxy immediately, sweep web proxy and DNS logs for recent queries to that domain, and hunt for ClickFix execution indicators (mshta/PowerShell spawned from browser or Run dialog) since the domain became malicious.
  • Leader — Plan: This demonstrates a new documentation-placeholder squatting attack class affecting thousands of open-source projects; task engineering to audit internal repos this quarter and add placeholder-domain checks to developer guidelines and repository scanning policy.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.