It basically goes:
* add their SDK, which has the ability to swizzle(swap out the implementation for) arbitrary methods in your app
* the swapped in implementations use JavascriptCore to execute javascript you supply, wrapping or replacing the 'real' invocation of the method.
* their SDK checks on startup which methods to replace and downloads the appropriate JS replacements
This is, technically speaking, only using JavascriptCore.