What happened

Manifold Security's research team came across third-party.com while reviewing public AI agent skills and MCP server documentation, where it is used as a sample endpoint. The same name turns up in the W3C Geolocation and Compute Pressure specifications, Chromium's Telemetry Extension API docs, Privacy Community Group proposals, and repositories from projects including Chromium, Sanity and Vercel, according to BleepingComputer's summary of the findings.

What a visitor gets depends on the platform. On Windows, the site shows a fake Cloudflare "verify you are human" check, puts a PowerShell command on the clipboard, and instructs the user to press Win+R, paste and run it. The command fetches a second stage from another domain. On macOS and Linux, the page shows an error saying the site requires a Windows PC. BleepingComputer found a VirusTotal scan from May 2, 2026 showing the script set up to download a 131 MB archive; at the time of its report the payload hosts no longer resolved, so the final payload could not be analysed.

The domain was first registered in 1996. Neither Manifold nor BleepingComputer could establish when or how control changed, so whether it lapsed and was re-registered or was sold is unconfirmed. The Hacker News, reporting the same research, adds that Manifold checked other unreserved placeholder names and found two more, yoursite.com and your-domain.com, also serving scams or scareware.

Manifold's point is simple. The names example.com, example.net and example.org are reserved by RFC 2606 so that documentation can use them safely. third-party.com was never on that list; it only looked like it belonged there.

Why it matters if you run public infrastructure

Every hostname your code, docs, tests or configuration mentions is a dependency, whether you think of it that way or not. A placeholder in a README is harmless until a developer copies it into a config file, a test fixture sends real requests to it, or an AI coding agent follows the link from a skill file and fetches whatever is there now. Manifold specifically flags agent skills and MCP documentation, where a model may treat a hard-coded URL as trusted input.

This is the same shape as the expired-domain problem in general: a domain that used to be harmless, or used to be yours, now belongs to someone else, and nothing in your stack notices. The references keep working. They just resolve to a stranger.

What to check this week

  1. Search your repositories and docs for third-party.com, and for other plausible placeholders such as yoursite.com, your-domain.com, mycompany.com and yourcompany.com. Replace them with example.com, example.org or example.net, or with a name under a domain you own.
  2. Check what your agent tooling can reach. Skill files, MCP server configurations and prompt templates that include sample URLs should use reserved names or your own domains.
  3. List external hostnames your production pages actually load. A placeholder that slipped into a template as a script or image source is a live third-party include.
  4. Keep your own lapsed domains in mind. A domain you stopped renewing but still reference in old emails, apps or documentation is an unreserved placeholder too, from an attacker's point of view.

How Attack Surface Scan covers this

Partly. Attack Surface Scan does not read your source code, repositories, documentation or agent configuration, so it cannot find a placeholder hostname sitting in a README or a test. That search is yours to run.

Where it helps is on the live side. The page crawl records every third-party script host referenced by your pages (see the third-party script inventory), so a placeholder that made it into a production page as a script source shows up as an external dependency you did not intend, and a script from another domain without an integrity hash raises web.third-party-script-no-sri. For your own domains, registration expiry is read from RDAP nightly with warnings at 60, 30, 14 and 7 days (see Domain registration hygiene), which is how you avoid becoming the next unreserved placeholder somebody else picks up. The crawl never connects to third-party hosts it finds; they are recorded, not scanned.

Sources