← All posts / Meta

359,000 Files, 349 Agent Skills, Two Unreserved Domains: The Placeholder-URL Scam On-Ramp Nobody Audits

Manifold Security traced how unreserved documentation placeholders like yoursite.com and your-domain.com — cited in 359,000 GitHub files and 349 AI agent skills — now funnel macOS visitors into scareware and investment fraud that every static scanner clears.

359,000 Files, 349 Agent Skills, Two Unreserved Domains: The Placeholder-URL Scam On-Ramp Nobody Audits

When a developer needs a fake URL for documentation, the honest instinct is to type something that is obviously not real. example.com exists for exactly this purpose — it is reserved under RFC 2606 by IANA and can never be registered by anyone. But a long habit of writing yoursite.com or your-domain.com instead has quietly built one of the strangest attack surfaces in modern software: hundreds of thousands of files that point at hostnames anyone can buy, and that somebody finally did.

Manifold Security’s latest disclosure, published September 27, documents what happens next. The two placeholder domains yoursite.com and your-domain.com — cited as URLs in over 359,000 GitHub files and 349 distinct AI agent skills in the firm’s corpus — today sit on parking services whose advertising chains selectively serve scams to macOS visitors and an ordinary ad-laden parking page to everyone else.

The numbers behind the surface

This is the second act of a story that began earlier in September, when Manifold revealed that third-party.com, a documentation placeholder hard-coded across 1,700+ repositories and a long tail of MCP-server docs and agent skills, had been turned into a ClickFix lure: a fake Cloudflare verification that places a PowerShell command on a Windows visitor’s clipboard and instructs them to run it.

The new sweep widened the lens. Manifold searched its corpus for every other unreserved placeholder domain of the same kind and found thirteen more, cited by 1,536 skills in total. Three of the fourteen are actively serving malicious payloads:

  • third-party.com — ClickFix clipboard malware, gated to Windows, with a second stage at elxxvvx.xyz.
  • your-domain.com — scareware and investment fraud. Its ad chain reached both a fake “MacOS Security Center” selling counterfeit McAfee renewals at 55% off and a counterfeit BBC News article promoting a financial scheme.
  • yoursite.com — investment fraud, reaching macOS visitors through a fake ZDFheute news article built around a talk-show confrontation between two German politicians that never happened.

Measured in raw citations, the ClickFix case is the small one. The two newly-named domains together dwarf it: 359,000 files versus 1,700 repositories, and roughly 350 affected skills versus the handful that cited third-party.com.

Why every static check passed

The most uncomfortable finding in the report is how cleanly the domains scan. Before rendering anything in a browser, Manifold ran the standard battery: registry RDAP lookups for ownership and recent transfers, blocklist history, twenty-one years of archived page sizes, and a 52-request probe varying the User-Agent across Windows, macOS and Linux. All thirteen domains came back clean.

They were clean because the lure is not hosted on the placeholder domains at all. The page you fetch is a legitimate-looking parking page; the redirect to the scam fires only after the page’s JavaScript executes, one hop away on another host. A text-only fetch — the thing virtually every automated scanner does — never sees the redirect, no matter how many User-Agents it rotates.

Blocklists fail for the same structural reason. A public blocklist added third-party.com on July 7 and dropped it ten days later, while the lure remained live throughout. A page that serves its payload to one operating system and a decoy to the rest will fingerprint clean from any scanner configured for the wrong one.

The scam infrastructure is equally evasive. The scareware’s exit function ships as a single line of obfuscated JavaScript that, deobfuscated, does two things: loads a hidden one-pixel conversion-tracking image, then navigates onward. The destination hostname never appears in the page’s source — it is assembled at runtime from the page’s own query string, which the upstream ad router populated with a click ID, a billing ID, and the next hop. Scanning the code yields nothing to block, and the operator can rotate routing domains without touching the page at all.

The business model is affiliate lead-gen

Following one exit chain, Manifold landed on an affiliate click tracker and then on a genuine McAfee landing page on mcafee.com, arriving with the affiliate-network parameters that credit a sale. The scheme is lead generation: fake virus warnings funnel frightened users into real McAfee subscriptions, and an affiliate collects a commission on each one. A scanner that follows the chain to its end sees a legitimate company, so every detection signal points at a brand that is itself a victim of the abuse.

Every other known entrance into the same scareware requires marketing — phishing mail, ads, search placement. Five other entry points observed in the week to September 23 were all bank and parcel lookalikes (scotiabank-secure.info, fedexsupportverification.com, lnterac-transfer-login.com with a lowercase L swapped for the I). The placeholder domains are the exception: their distribution channel is documentation people already trust, copied into thousands of repositories. It is the one entrance the operator did not have to build.

Why agents are the exposed reader

These pages are engineered for a human at a browser, and a discerning human usually escapes. The more exposed reader, as Manifold puts it, is an AI agent. Agents fetch and act on the documentation these citations live in — READMEs, skill definitions, MCP configs — and the population most likely to be susceptible runs on cheaper, smaller models tuned for speed and economy rather than skepticism.

The historical record makes clear that the citing projects are victims, not accomplices. Where git history dates the third-party.com lines, they went in on January 19 and February 28, 2026 — months before the domain began serving its lure in June. Nothing in a skill file has to change for the ground to shift underneath it; one affected skill has since been forked 1,089 times, and every fork carries the line. Two of the repositories citing yoursite.com are security projects, including the Modern Honey Network and a red-team TTPs reference.

The fix is a habit, not a tool

The remediation is almost embarrassingly simple. Stop citing domains you do not control in documentation an agent may read. example.com, example.org and example.net are IANA-reserved and can never be registered; every domain in Manifold’s table can be bought this afternoon. For corpus maintainers, the report’s advice is to replace “is this domain on a blocklist” with “who owns it now, and what does its advertising chain do today, on the operating system my readers run” — a runtime question, not a static one.

The deeper lesson generalizes beyond placeholder domains: assumptions embedded in documentation go stale, and only re-verification at fetch time catches what changed. The 349 skills in this corpus will be patched slowly, if at all. The domains will keep changing hands. The gap between those two clocks is the attack surface.