Threat · curated 24 Sep 2026

Placeholder Domains Whose Ads Serve Scams

Coverage timeline

discovered manifold.security primary 24 Sep 2026thehackernews.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Hard-coded placeholder domains embedded in over 1,500 AI agent skills turn a documentation convenience into a live supply-chain vector that can route agents and their users to attacker-controlled malware and scam pages.

Manifold Security disclosed that unreserved documentation placeholder domains—third-party[.]com, your-domain[.]com and yoursite[.]com—have been registered by attackers and now serve malicious content, including a Windows-gated ClickFix PowerShell lure and macOS scareware/investment-fraud scams via cloaked ad redirects. These domains are hard-coded across 1,700+ GitHub repositories and referenced by more than 1,500 AI agent skills, so every agent, doc, test, or skill pointing at them now directs users to attacker infrastructure. Static text checks miss the threat because the redirect fires only after JavaScript runs in a real browser.