Because the script is being run in the context of the trusted web site, it has access to cookies such as session tokens, as well as any other user information available within the security context of that web site.
FORBES: Security Firm F-Secure Has Security Flaw In Web Site