The record
Written by software from the 1 report below. The points restate them; where one says why it matters, that is Prism's reading, not a reported fact.
- The domain third-party.com, previously used as a generic documentation placeholder, is now being used to host malicious ClickFix lures.
- Users visiting the site from Windows devices are tricked into running PowerShell commands that compromise their systems.
- The domain is referenced in over 1,700 public GitHub repositories, creating a widespread supply chain risk.
- Researchers identified thirteen other unreserved placeholder domains currently being used for similar malicious activities.
What to watch next
- Ongoing remediation of documentation referencing the identified placeholder domains
- Future discovery of additional weaponized placeholder domains
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Cody Nash
security researcher
2 quotes · 1 outlet
“On a macOS browser, your-domain[.]com showed a fake 'MacOS Security Center' claiming four viruses and selling a counterfeit McAfee renewal at 55% off”
In the article
…identified 13 more placeholder domains that are not IANA-reserved, with two of them – yoursite[.]com and your-domain[.]com – serving scams and scareware to macOS visitors and an ordinary parking page to other users. " On a macOS browser, your-domain[.]com showed a fake 'MacOS Security Center' claiming four viruses and selling a counterfeit McAfee renewal at 55% off ," security researcher Cody Nash said. "On another macOS render, yoursite[.]com showed a counterfeit ZDF news article advertising an investment scheme." The complete list of domains, each of them are pass static checks,…
“Scareware and investment fraud are a lower threat than clipboard malware, the exposure they ride on is far larger, and none of it showed up in any static check we ran”
In the article
…- acme[.]com - company[.]com - mycompany[.]com - vendor[.]com - foo[.]com To make matters worse, the two scam-scarware-serving sites are present in hundreds of thousands of GitHub files and hundreds of agent skills. " Scareware and investment fraud are a lower threat than clipboard malware, the exposure they ride on is far larger, and none of it showed up in any static check we ran ," Nash said.…
Coverage1
All filed from India
Named United States · GitHub · third-party.com · Ax Sharma · Cody Nash · Google · Manifold Security · VirusTotal
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the reports above, or say they can't.
