It will if the attacker uses the same custom name for his field.
The attacker could try to suck as much data as possible by creating thousands of hidden fields having a lot of possible combinations for the names of these non-standard CC fields, and wait to get lucky.
It looks awesome, but I have an error when I connect my google calendar. The header shows 'connexion failed', and the console says :
appBundle.js:454 Uncaught QuotaExceededError: Failed to execute 'setItem' on 'Storage': Setting the value of 'oneview_allEvents' exceeded the quota.