Possible supply-chain "attack" (or demonstration, from what I can tell) on wherever they get their polyfill library? It's coming from:
https://polyfill.archive.org/v3/polyfill.min.js?features=fet...
https://polyfill.archive.org/v3/polyfill.min.js?features=fet...
Also, the vulnerability seems to be a domain overtake. But Archive is self hosting a static version of the dependency?