# Developer placeholder domain serves fake security check

_Published Wednesday, September 23, 2026 at 9:08 PM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Developer placeholder domain serves fake security check — Primary](https://www.bleepstatic.com/content/posts/2026/09/23/third-party-clickfix-red.jpg)

The domain third-party.com, used as a placeholder in developer documentation, is serving a fake Cloudflare verification page that tries to make Windows users run a PowerShell command, BleepingComputer confirmed. Unlike domains reserved for examples, third-party.com is a registered address whose content can change.

Clicking the page's verification box copies a command to the clipboard; the page then instructs users to paste and run it. The command attempts to download and execute a script. At the time of testing, the payload domain no longer resolved, and there were no reports that documentation links had caused the attack to execute on developers' devices.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/)

---
Canonical: https://techandbusiness.org/newswire/kUtv49-68Ofb6G6QK81e2e
Published: 2026-09-24T01:08:44.167Z
Story chronology: 2026-09-23T22:46:01.000Z
Retrieved: 2026-09-24T03:36:51.794Z
Publisher: Tech & Business (techandbusiness.org)
