Attacker origin:
indexOf(".swaven.com"): → PASSES the old wtbLoader.js check
endsWith(".swaven.com"): → new loader.js would BLOCK this
How it works: This page opens hungry-man.com/where-to-buy (a real Swaven/MikMak customer).
That page natively loads the legacy wtbLoader.js which checks origin.indexOf(".swaven.com").
Our attacker origin passes that check. We send postMessage with wtb:serverTracking + arbitrary script.