The domain third-party.com — long used, like example.com, as a stand-in for an arbitrary external service in developer documentation — is now serving a fake Cloudflare "Performing security verification" page that copies a malicious PowerShell command to the clipboard and instructs the visitor to paste it into Windows Run. Manifold Security found the abuse while examining public AI skills and MCP server documentation, and BleepingComputer confirmed the page live. The loaded PowerShell reconstructs a payload URL at elxxvvx[.]xyz/f, downloads a script and executes it; a May 2026 Hybrid Analysis report shows the same infrastructure serving an update2.zip archive that extracted to an executable named draw.io.exe. The domain was registered in 1996 and there is no determination of when control changed, and no confirmed case of the ClickFix chain executing on a developer's machine. The structural point is that, unlike the IANA-reserved example.com family, third-party.com is an ordinary registrable domain that its owner can repoint at will — and it sits inside documentation, repositories and AI tool descriptors that automated agents now read and follow.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-25 |
| Source | BleepingComputer |
| Reliability | Tier 2 |