The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem.
It’s an interesting site to target. Web developers frequently use the third-party[.]com domain as a stand-in for another website in code or documentation, so the malware poses a serious risk to enterprises who may be inadvertently sending employees or customers to the malicious site.
A more familiar placeholder domain is example.com — but this, like example.org and a handful of others, is reserved by IANA, the Internet Assigned Numbers Authority, so no-one can register it.



