Payloads

Let there be magic !
 

Capture 

Scripts that will capture user inputs, save screenshots, take snapshots...

Anyway to retrieve information related to the user or its behavior.

System 

Perform network and system operations from the browser executing the script.

From system fingerprinting to network DDoS via portscans and network info collection.

Browsing 

Anything that can be used to alter users browsing experience, or take over the injected browser.

Shells, local storage leaks and corruption, forced downloads, CSRF, token theft and more !

More... 

If you didn't find what you are looking for in ither categories, it may be here...

Some obfuscation stuff, script loaders, C&C, device specific operations... A true Aladdin's cave