BuzzFeed Inc. dfpNativeTemplate postMessage → DOM-XSS

Attacker origin: — contains buzzfeed.com, so it passes the shared postMessage origin gate on every property below. Click a target: it opens that site and injects the malicious native-ad card; on success the payload runs alert(document.domain) in that origin and beacons proof back here.

Reachability: the gate accepts this origin on all four, but the payload only renders where a native display_card slot is mounted. Confirmed firing on BuzzFeed. HuffPost (doesn't load the SDK), BuzzFeed News (archived), and Tasty (no display-card slot) accept the message but mount no sink on their current pages.

idle