Threat · curated 24 Sep 2026
Placeholder Domains Whose Ads Serve Scams
First reported manifold.security
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Hard-coded placeholder domains embedded in over 1,500 AI agent skills turn a documentation convenience into a live supply-chain vector that can route agents and their users to attacker-controlled malware and scam pages.
Manifold Security disclosed that unreserved documentation placeholder domains—third-party[.]com, your-domain[.]com and yoursite[.]com—have been registered by attackers and now serve malicious content, including a Windows-gated ClickFix PowerShell lure and macOS scareware/investment-fraud scams via cloaked ad redirects. These domains are hard-coded across 1,700+ GitHub repositories and referenced by more than 1,500 AI agent skills, so every agent, doc, test, or skill pointing at them now directs users to attacker infrastructure. Static text checks miss the threat because the redirect fires only after JavaScript runs in a real browser.