According to research published on September 23–24 by security startup Manifold Security, unreserved placeholder domains that were used for years only as "examples" in developer documentation have been registered by attackers and now resolve to live malicious pages. References to these domains are hardcoded across hundreds of thousands of GitHub files and roughly 349 AI agent skills — exposing the automated agents that read and call those URLs.
What Happened — When an Example Domain Becomes a Weapon
The pivot point is reservation. Domains like example.com, example.org, and example.net are permanently reserved by IANA for documentation (RFC 2606), so no one can register them. Domains such as third-party.com, yoursite.com, and your-domain.com, by contrast, were merely treated as examples — they were never reserved, so anyone can buy them. Attackers walked straight through that gap. Manifold's research (led by Head of Research Ax Sharma and researcher Cody Nash) confirmed the domains are hardcoded not only in GitHub code and docs but inside AI agent skills.
GitHub files referencing yoursite.com 185,000+
Referencing your-domain.com 174,000+
Repositories referencing third-party.com 1,700+
What Each Domain Delivers
The same "example domain" delivers different payloads depending on who now owns it. Here is what Manifold observed across the three domains.
| Domain | Malicious content served | Primary target |
|---|---|---|
| third-party.com | ClickFix malware (fake Cloudflare check → clipboard poisoning → PowerShell execution) | Windows |
| yoursite.com | Investment fraud disguised as fake news articles | macOS |
| your-domain.com | Scareware (fake macOS security alerts) and investment fraud | macOS |
In particular, yoursite.com and your-domain.com were seen impersonating a bogus "macOS Security Center" to push fraudulent McAfee renewals, and using counterfeit BBC News and ZDFheute articles to funnel victims toward investment-scam pages.
How ClickFix Infects
The ClickFix lure on third-party.com is social engineering. A page disguised as a Cloudflare or reCAPTCHA verification screen appears, and behind it JavaScript silently copies a malicious command into the victim's clipboard. The page then instructs the user to "press Windows Key + R, paste with Ctrl+V, and run it to complete verification." Anyone who follows along executes a PowerShell command that pulls and runs code from a remote server (elxxvvx[.]xyz).
Manifold summed up the danger this way: "The victim runs the attacker's command with their own permissions, and no file was ever downloaded for an antivirus to catch." According to security vendor ESET, ClickFix campaigns surged 517% between late 2024 and mid-2025.
Why Scanners Missed It — the Cloaking Trap
The campaign survived so long because it screens its visitors — a technique called cloaking. Windows users get the full ClickFix lure and macOS users get scareware, but a request from a Linux or datacenter IP receives an ordinary parking page. On top of that, the malicious redirect only fires after the page's JavaScript runs, so static checks and reputation scanners that only fetch text never see the lure. As Manifold put it, "the redirect to the scam fires after the page's JavaScript runs, so a text fetch never sees it, whatever User-Agent you send."
Why This Is Especially Dangerous for AI Agents
The real severity comes from automation. AI agents tend to trust and call URLs written in skill and tool documentation as-is, inheriting the risk of domains their authors never intended to be malicious. Manifold called it "the curl | bash problem wearing a different hat," warning that "a domain you trust today can change hands tomorrow, and the trusted endpoint simply starts returning something else." Public skills found citing the placeholders include shopify-expert (in jeffallan/claude-skills, ~11,000 stars), alova-server-usage, and dynamic-dashboard-builder, with traces also surfacing in Chromium's developer docs, Sanity's Playwright testing skill, and Vercel's Turborepo unit tests.
What to Do About It
Manifold's guidance is direct. Use only RFC 2606-reserved domains (example.com, example.org, example.net, or .example) as examples in documentation and skills, and never cite — or allowlist — a live domain you do not control. Teams should sweep already-published skills, tests, and docs for unreserved placeholders like third-party.com, yoursite.com, your-domain.com, and yourcompany.com, and replace them.
What It Means Going Forward
The incident is a warning about how the AI agent ecosystem will govern its "supply chain of trust." As architectures in which agents autonomously call URLs from documentation spread, every static URL embedded in a skill becomes a promise that can break at any time. A seemingly trivial convention — the example domain — has turned into a large attack surface, and both skill publishers and framework providers now need basic hygiene that makes reserved domains the default.
· Manifold Security — Placeholder Domains Whose Ads Serve Scams (original research)
· Manifold Security — third-party.com Placeholder Now Serves ClickFix
· The Hacker News — third-party.com Referenced Across 1,700+ Repos Now Serves Malicious Content
· HackRead — Placeholder Domains Used by 349 AI Agent Skills Redirecting to Scams
- Unreserved placeholder domains once used as documentation examples (third-party.com, yoursite.com, your-domain.com) were registered and now serve malicious content
- Roughly 349 AI agent skills and hundreds of thousands of GitHub files reference these domains
- third-party.com pushes ClickFix to Windows users; the others serve macOS scams and scareware via cloaking
- Because agents call skill URLs as-is, the supply-chain risk propagates automatically
- Fix: use only RFC 2606-reserved example domains and audit/replace them in existing skills and docs