I've seen this. This is the same basic payload/TTP from the regional news sites that were compromised (via shared scripts hosted by McClatchy and MediaNews) a few years ago (2019). Op needs to hit the site with a new IP and with a 'referer' to get the second stage. There is also some JS fingerprinting, like checking GPU model, to ensure a plausible client visit. This was a fun piece of malware to dissect.
I believe Symantec classified it as SocGholish.
Edited: clarity, details