A long-trusted placeholder domain used in countless code snippets and documentation has been weaponized in a new campaign, posing a direct risk to software integrity. Security researchers have revealed that third-party[.]com, a generic URL frequently used as an illustrative example, is now actively serving malicious payloads to Windows users.
The domain functioned for years much like the officially reserved example.com—a safe, inert reference for developers. However, unlike example.com which has permanent protection from the Internet Assigned Numbers Authority (IANA), third-party[.]com remained an unregistered, vulnerable name. That changed when malicious actors registered it, leveraging its widespread trust.
According to a report from The Hacker News, the hijacked domain is embedded in over 1,700 public code repositories. The attack is surgically targeted: Windows users are served a "ClickFix" lure via their browsers, designed to trick them into executing malware, while visitors from other operating systems see a harmless decoy. This OS-specific filtering helps the campaign evade many automated security scans and researcher tools that typically run on Linux or macOS.
The incident exposes a critical oversight in development hygiene. It demonstrates that any external reference—be it a URL in a README, a comment in a configuration file, or a tutorial example—can become an attack vector if not rigorously vetted. The implicit trust placed in a domain solely due to its common usage proved to be a systemic vulnerability.
Security experts, including researchers at Manifold Security cited in the report, have issued an urgent call for action. All development teams must immediately audit their codebases, documentation, and dependency files for any occurrence of third-party[.]com. The domain must be replaced with a genuinely safe alternative.
The recommended substitutes are IANA-reserved domains such as example.com, example.org, or example.net. These names carry structural guarantees against hijacking and are safe for indefinite illustrative use.
This advisory applies to developers and organizations worldwide. Auditing internal and public repositories to eliminate references to this compromised domain is a vital step in safeguarding the software supply chain. Proactive verification of all third-party references is now an essential security practice.
一個長期以來被無數代碼片段與文件引用、備受信任的佔位域名,已成為新一輪攻擊活動的武器,對軟件完整性構成直接風險。安全研究人員披露,常用於範例說明的通用網址 third-party[.]com,現正向 Windows 用戶主動投放惡意載荷。
該域名多年來一直像官方預留的 example.com 那樣運作——為開發者提供安全、無害的參考示例。然而,與受互聯網號碼分配機構(IANA)永久保護的 example.com 不同,third-party[.]com 此前是個未註冊且易受攻擊的域名。當惡意行為者註冊該域名並利用其廣泛的信任度後,情況發生了根本轉變。
據 The Hacker News 報導,這個遭劫持的域名已嵌入超過 1,700 個公共代碼倉庫。攻擊具有高度針對性:Windows 用戶透過瀏覽器收到「ClickFix」誘騙提示,欺騙他們執行惡意軟件,而其他作業系統的訪問者則看到無害的偽裝內容。這種針對作業系統的過濾機制,讓攻擊活動能夠規避許多在 Linux 或 macOS 上運行的自動化安全掃描與研究工具。
此事件暴露了開發流程中一個關鍵的疏忽。它證明任何外部引用——無論是 README 中的網址、設定檔中的註釋,還是教程中的範例——若未經嚴格審查,都可能成為攻擊向量。僅因普遍使用而對域名產生的隱含信任,已被證實是個系統性的安全漏洞。
安全專家,包括報告中引用的 Manifold Security 研究員,已發出緊急行動呼籲。所有開發團隊必須立即審查其代碼庫、文件及依賴文件中所有出現 third-party[.]com 的地方,並替換為真正安全的替代方案。
建議的替代方案是 IANA 預留域名,如 example.com、example.org 或 example.net。這些名稱具有防止劫持的結構性保障,可安全無限期用於示意用途。
此公告適用於全球開發者與組織。審查內部及公共倉庫以消除引用此遭入侵域名,是保障軟件供應鏈安全的關鍵步驟。主動驗證所有第三方引用現已成為必不可少的安全實踐。
