New Function() is just another name for eval(). It has nothing specificly to do with css.
It may have access to the window object, however, so if something important is there, if can probably mess with that.
> why would you eval() CSS?
It’s really as simple as “because you can”. This is just an obfuscation technique.
So, the hackers need to have access both to CSS and HTML to put the malicious JS that looks innocent in the HTML and load the malicious JS from the CSS.
Now it makes sense, thanks.