Tendvane

← All articles

ScamsSeptember 24, 2026

The domain in a thousand code samples now tells you to press Windows+R

Search open-source code for third-party.com and you find it in more than 1,500 files across 1,700-odd repositories, Chromium included. It has been the polite stand-in for somebody else's website in documentation for close to thirty years. It is also a real domain that a real person owns, and right now it serves malware.

Manifold Security spotted it while reading through public AI skills and MCP server documentation, and the finding was reported on 23 September. Load the domain on a Windows PC and you get a fake Cloudflare screen: "Performing security verification", a tick box, the whole familiar wait. Click the box and a PowerShell command is copied to your clipboard without a word, and the page walks you through pressing Windows+R, Ctrl+V, Enter. That pulls a script down from a second address and runs it. Visit the same page from a Mac or a Linux machine and it just tells you your operating system is not supported.

The reason this was possible at all is dull and important. IANA reserves example.com, example.net and example.org precisely so nobody can ever own them. third-party.com is an ordinary registration from 1996 with none of that protection, and whoever controls it decides what appears. The campaign has been running since at least June.

The defence here is a habit, not a setting. No website ever needs you to press Windows+R and paste something in. That box runs commands on your PC, and Microsoft's own analysis of this trick describes it as a trusted corner of Windows that attackers have learned to borrow. If a CAPTCHA asks for anything more than a click, close the tab and go somewhere else. Tendvane's safety check goes through what is installed and running and flags what turned up uninvited, which is usually what a pasted command leaves behind.

Sources

Download Tendvane