Why there's "new Function()" that looks for CSS computed styles with "--script"? Is this some pattern with a popular JS framework?
> Is this some pattern with a popular JS framework?
I've never seen this anywhere before, JS grabbing values from CSS, but I mostly done ClojureScript development for the last 2 years.
> why would you eval() CSS?
It’s really as simple as “because you can”. This is just an obfuscation technique.
So, the hackers need to have access both to CSS and HTML to put the malicious JS that looks innocent in the HTML and load the malicious JS from the CSS.
Now it makes sense, thanks.
It may have access to the window object, however, so if something important is there, if can probably mess with that.