After pressing "Sign in", the user’s credentials are sent to a PHP script on a compromised web server.
I might be missing something, but how does this part work?
Is it because the document in the Google Drive folder is actually a html document that the browser is loading (and executing javascript of)?