It looks like `--script` is just an arbitrary string, it is only executed because a real `<script>` tag retrieves the property and evals it through `(new Function())()? https://twitter.com/sansecio/status/1336614850047381506/phot...
> why would you eval() CSS?
It’s really as simple as “because you can”. This is just an obfuscation technique.
So, the hackers need to have access both to CSS and HTML to put the malicious JS that looks innocent in the HTML and load the malicious JS from the CSS.
Now it makes sense, thanks.
It may have access to the window object, however, so if something important is there, if can probably mess with that.
> Is this some pattern with a popular JS framework?
I've never seen this anywhere before, JS grabbing values from CSS, but I mostly done ClojureScript development for the last 2 years.