Post author, what website were you visiting that was served over http:// allowing a data injection to occur?
Have you contacted them to warn them that Xfinity is injecting JS into their site, and asked them to implement HTTPS+HSTS to protect against that?