That's my impression too, because no one would manually add plain text JS to a .gz file, but wouldn't that imply that someone has broken into so many AWS accounts that they needed a script to hack them all!?
I hope not, but that may be occurring. I would check your access history/see what users have touched it, and I would certainly contact Amazon.