That company is so compromised and/or inept. From another tweet:
  1. They are loading Javascript from a CDN (Content Delivery Network).
  2. They are not version-locking loaded Javascript.
  3. They had their CDN compromised.
ELI5 version: