dfpNativeTemplate postMessage → DOM-XSSAttacker origin: — contains buzzfeed.com, so it
passes the shared postMessage origin gate on every property below. Click a target: it
opens that site and injects the malicious native-ad card; on success the payload runs
alert(document.domain) in that origin and beacons proof back here.
Reachability: the gate accepts this origin on all four, but the payload only
renders where a native display_card slot is mounted. Confirmed firing on
BuzzFeed. HuffPost (doesn't load the SDK), BuzzFeed News (archived), and Tasty
(no display-card slot) accept the message but mount no sink on their current pages.