A domain once used as a harmless documentation placeholder has been weaponized, creating a critical supply-chain vulnerability that affects thousands of public code repositories.

Security researchers at Manifold Security report that the domain third-party.com, commonly used as a stand-in for external resources in tutorials and README files, is now serving malicious content. The attack uses a targeted approach: visitors using Windows browsers are shown a "ClickFix" social engineering lure, which attempts to trick them into running malicious commands. Users on other operating systems or automated scanners are directed to a benign page, making the threat harder to detect.

The potential impact is widespread. The domain is referenced in more than 1,700 public GitHub repositories. Its use as a generic, non-functional example domain—similar to the officially reserved example.com—created this blind spot.

The root cause is a lack of official reservation for third-party.com. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," explained Ax Sharma, Head of Research at Manifold Security. Unlike example.com, which is permanently reserved by the Internet Assigned Numbers Authority (IANA), third-party.com was available for public registration. This oversight allowed an attacker to claim the domain and silently redirect all traffic pointing to it.

This incident highlights a severe gap in software supply chain hygiene. Developers routinely copy code snippets and examples without scrutinizing embedded external references. An unreserved placeholder becomes a latent threat; once registered by a malicious actor, it can compromise any system, tool, or documentation that relies on it.

In response, security experts are issuing an urgent advisory for development teams. The first priority is to audit all internal and public codebases for any occurrence of third-party.com. Every reference should be replaced with IANA-reserved domains such as example.com, example.org, or example.net.

For long-term protection, organizations must review and update their coding and documentation standards. Policies should mandate the use of reserved domains in all samples and templates. This attack also underscores the need for better static analysis tools capable of detecting and flagging references to unreserved or potentially hostile domains in source code and dependency files.

The compromise of third-party.com is a stark reminder: in modern software development, even an inert placeholder URL can become a potent attack surface if left unmanaged. Security must encompass all project components, from core code to boilerplate, templates, and documentation.


一個曾用作無害文件佔位符的域名現已被武器化,形成了一個嚴重的供應鏈漏洞,影響數千個公共程式碼倉庫。

Manifold Security 的安全研究人員報告指出,域名 third-party.com——在教程和 README 文件中常用作外部資源的代替符號——目前正提供惡意內容。此次攻擊採用了具針對性的手法:使用 Windows 瀏覽器訪問的用戶會看到一個「ClickFix」社交工程誘餌,企圖誘騙他們執行惡意指令。其他作業系統的用戶或自動化掃描器則會被引導至無害頁面,令威脅更難被偵測。

潛在影響範圍甚廣。該域名在超過 1,700 個公共 GitHub 倉庫中被引用。它被用作通用、非功能性的範例域名——類似於官方預留的 example.com——這一做法造成了此盲點。

根本原因在於 third-party.com 未經官方預留。Manifold Security 研究主管 Ax Sharma 解釋道:「third-party.com 多年來一直是通用文件佔位符,扮演著與 example.com 相同的角色。」與永久由互聯網號碼分配機構 (IANA) 預留的 example.com 不同,third-party.com 當時可供公眾註冊。此疏漏令攻擊者得以惡意接管該域名,並靜默地重新導向所有指向它的流量。

此事件凸顯了軟件供應鏈衛生方面的嚴重缺口。開發者常複製貼上程式碼片段和範例,卻未仔細審查其中嵌入的外部引用。一個未經預留的佔位符會成為潛在威脅;一旦被惡意行為者註冊,任何依賴它的系統、工具或文件都可能被危害。

作為回應,安全專家正向開發團隊發出緊急通告。首要任務是審計所有內部和公共程式碼庫中所有出現 third-party.com 的地方。每個引用都應替換為 IANA 預留的域名,如 example.com、example.org 或 example.net。

為提供長期保護,各組織必須審查並更新其編碼和文件標準。政策應強制在所有範本和樣板中使用預留域名。此次攻擊亦強調了改進靜態分析工具的必要性,以便能偵測並標記原始程式碼及依賴項檔案中對未預留或潛在惡意域名的引用。

third-party.com 被惡意接管的事件是一個鮮明提醒:在現代軟件開發中,即使是一個看似無害的佔位符 URL,如果疏於管理,也可能成為強大的攻擊面。安全性必須涵蓋項目所有組件,從核心程式碼到樣板、範本及文件。

新聞來源 / Original News Source