Attacker sits at network / ISP level, and can therefore inject any (js, ...) payload in non-https web pages, on the fly.
Nope, nothing of the sort.
The government has absolute control over the internet infrastructure here, and they manipulated the page's markup on the fly (or maybe the served an already modified and cached copy) when requested.