The placeholder domain third-party.com, widely used in developer documentation as an example hostname, is now serving ClickFix attacks that impersonate Cloudflare verification pages to trick Windows users into executing malicious PowerShell commands. Unlike IANA-reserved documentation domains, third-party.com is a normally registered domain whose owner can control its content, creating a security vulnerability for developers who copy example code literally.