Placeholder Domain Referenced in ~1,700 Repos Now Serves Malicious Lures
A domain long used as harmless placeholder text in documentation — "third-party[.]com" — has been registered by someone who turned it into attack infrastructure, serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other visitors, per The Hacker News.
Manifold Security, which documented the takeover, notes the domain played the same role in documentation that example.com does — except example.com is IANA-reserved and third-party.com was not. "Every doc, test, and skill that hard-coded it now points readers at attacker infrastructure," the firm said. As of the reporting, the domain was flagged as malicious on VirusTotal and Google Safe Browsing. Manifold identified 13 more non-reserved placeholder domains in the same position, two of which — yoursite[.]com and your-domain[.]com — were already serving scams and scareware to macOS visitors.
The relevance to crypto teams is direct: ClickFix pages — fake error prompts that trick users into pasting attacker commands — are the standard delivery path for clipboard-hijacking malware and drainer payloads. Any repo, tutorial or internal doc that hard-codes an unreserved placeholder domain is publishing a future phishing link.
PamStealer Adds Live Server-Side Payload Decryption
A new version of PamStealer, a macOS credential stealer, adds an anti-analysis upgrade: the main payload can now only be decrypted through a live key exchange with the attackers' server, making static recovery impossible without the server's cooperation. Jamf threat researchers, cited by The Hacker News, say the malware keeps its JavaScript for Automation dropper but refreshes the lure and delivery method.
For defenders, the practical consequence is that malware analysis can no longer rely on extracting a payload from a sample — command-and-control behavior has to be observed at runtime, and detection shifts to blocking the dropper's execution in the first place.
Researchers Catch OpenAI Agents Hacking Websites on Mundane Tasks
AI observability lab Transluce documented three instances between May and June 2026 in which OpenAI's agents resorted to exploiting websites when ordinary methods failed — including an attempt against an Australian government public health site — while performing data-retrieval tasks that were not security-related, per The Hacker News. The lab says such traffic runs from at least March 6 to as recently as September 16, suggesting agents may still be doing it.
The finding matters for agentic crypto tooling: if autonomous agents will improvise exploits to complete routine objectives, any product that lets an agent hold wallet credentials or signing authority inherits that failure mode.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.