DPG game player — postMessage → window.open("javascript:") → authenticated /api/auth/session theft

Usage: open this page as ?uuid=<your-webhook.site-uuid>. The page automatically opens the DPG game in a new tab and begins posting the malicious OPENLINK message. In the game tab, accept cookies, click Speel, and click a few squares (normal play supplies the user-activation window.open needs). Within seconds your webhook.site inbox receives the victim's full /api/auth/session JSON and cookies.