A foundational convention in software development has been weaponized. The domain third-party.com, a ubiquitous placeholder in code samples and documentation for years, has been hijacked to serve malicious payloads, creating a widespread and latent threat across thousands of projects.

Security researchers at Manifold Security uncovered that the domain now operates a sophisticated, evasive campaign. Visitors using Windows browsers are redirected to a "ClickFix" lure, which tricks users into executing malware. Users on macOS, Linux, or automated scanners see a harmless decoy, allowing the threat to persist undetected by conventional tools.

This attack fundamentally breaks a long-standing trust model. Developers have historically treated domains like third-party.com and example.com as inert, illustrative stubs. While example.com is permanently reserved by IANA for this purpose, third-party.com was not, allowing malicious actors to purchase it. The result is a dormant supply chain risk: any reference to this domain in a repository now points to a poisoned resource.

The exposure is vast. Analysis shows third-party.com is referenced across more than 1,700 GitHub repositories. These references, embedded in comments, tutorials, and configuration templates, could be copied into active code or processed by automated build systems, injecting a malicious connection into development environments and, potentially, production infrastructure.

This incident transforms a passive documentation element into an active component of the software supply chain attack surface, highlighting a critical erosion of trust in standard development practices.

Immediate Actions Required: Developer Audit Guide

To mitigate this risk, developers and security teams must act decisively. Follow these steps to audit and sanitize codebases:

  1. Scan for Exposure: Search all repositories for the string third-party.com. Utilize grep, GitHub code search, or IDE-wide searches.
  2. Assess the Risk: Classify each finding. References within illustrative code snippets or comments are lower risk, but any instance in configuration files, scripts, or executable code is a high-priority threat.
  3. Sanitize and Replace: Replace all functional instances with a safe, canonical alternative. The IANA-reserved example.com (or .org/.net) is the correct standard. Do not simply remove the placeholder; replace it with a safe one to maintain documentation integrity.
  4. Enforce Preventative Controls: Update project .gitignore files, linting rules, and contribution guidelines to explicitly block third-party.com and enforce the use of reserved example domains.
  5. Spread Awareness: Circulate this advisory. This event is a lesson that all "safe" external resources in code must be re-evaluated for potential hijacking.

The hijacking of third-party.com is more than a singular malware campaign; it is a stark reminder of the fragile underpinnings of digital trust. For the open-source ecosystem, it necessitates a re-examination of how we reference the external world in our code, prioritizing officially sanctioned resources over community conventions that can be turned against us.


軟件開發中一個基礎性的慣例已被武器化。多年來在程式碼範例和文件中普遍使用的佔位域名 third-party.com 已被劫持,用於投放惡意載荷,在數以千計的專案中造成了廣泛且潛伏的威脅。

Manifold Security 的安全研究人員發現,該域名目前正運行一個複雜且善於規避的攻擊行動。使用 Windows 瀏覽器的訪問者會被重定向到一個「ClickFix」誘騙頁面,該頁面會欺騙用戶執行惡意軟件。而 macOS、Linux 用戶或自動化掃描器則會看到一個無害的誘餌,這使得威脅能避開傳統工具的檢測而持續存在。

此次攻擊從根本上打破了長期以來的信任模式。開發者過去一直將 third-party.com 和 example.com 這類域名視為惰性的、用於說明的佔位符。儘管 example.com 已由 IANA 永久保留用於此目的,但 third-party.com 並未被保留,這使得惡意行為者得以購買它。其結果是產生了一個休眠的供應鏈風險:程式碼倉庫中任何對此域名的引用,如今都指向了一個被毒化的資源。

暴露範圍極為廣泛。分析顯示,third-party.com 在超過 1,700 個 GitHub 倉庫中被引用。這些嵌入於註釋、教學和配置範本中的引用,可能被複製到活躍的程式碼中,或被自動化建構系統處理,從而將惡意連結注入開發環境,並可能進入生產基礎設施。

此事件將一個被動的文件元素轉變為軟件供應鏈攻擊面的一個主動組件,凸顯了標準開發實踐中信任的嚴重侵蝕。

立即行動要求:開發者審計指南

為了降低此風險,開發者和安全團隊必須果斷行動。請遵循以下步驟審計和清理程式碼庫:

  1. 掃描暴露情況: 在所有倉庫中搜索字串 third-party.com。可使用 grep、GitHub 程式碼搜尋或 IDE 全域搜尋。
  2. 評估風險: 對每項發現進行分類。位於說明性程式碼片段或註釋中的引用風險較低,但位於配置文件、腳本或可執行程式碼中的任何實例都屬於高優先級威脅。
  3. 清理並替換: 將所有功能性實例替換為安全的、符合規範的替代項。由 IANA 保留的 example.com(或 .org/.net)是正確的標準。請勿簡單地移除佔位符;應將其替換為安全的佔位符,以維護文件的完整性。
  4. 強制執行預防性控制: 更新專案的 .gitignore 文件、程式碼風格規範和貢獻指南,明確禁止使用 third-party.com 並強制使用保留的範例域名。
  5. 提升意識: 傳閱此安全公告。此次事件是一個教訓:程式碼中所有「安全」的外部資源都必須重新評估其被劫持的可能性。

third-party.com 的劫持不僅僅是一次單一的惡意軟件攻擊;它是數碼信任脆弱基礎的一個鮮明提醒。對於開源生態系統而言,它要求我們重新審視如何在程式碼中引用外部世界,並優先考慮官方認可的資源,而非可能被用來對付我們的社群慣例。

新聞來源 / Original News Source