baidu.com is not distributing the script. A proxy is taking advantage of unsecure connections (http) to serve the malicious script instead of baidu's script.
I don't know if what's the reasoning behind that.
If you ever manage to load that CDN over HTTPS/QUIC it sets a HSTS header so all further pageloads will go over HTTPS.
One reason may be that http makes it easier for surveillance or injection.