That's cloudflare. Every cloudflare site has a virtual /cdn-cgi directory:
https://news.ycombinator.com/cdn-cgi/images/spinner-2013.gifThe obfuscated javascript seems to solve a challenge response riddle that is then submitted back (to cloudflare) and confirmed to be correct on cloudflares proxy servers. The obfuscation is probably there to prevent simple ddos attack tools from just parsing out the response.
I built something similar to that for a client. When doing DDOS prevention you have to detect malicious clients. In a simple setup you only have the very first request and you have to decide whether to allow or deny it. So all you have are request headers and various metadata (for example geoip, etc). It's hard to do that.
What cloudflare does is to first serve the page you saw if the browser doesn't provide a cookie that cloudflare sets (delete all cookies and the cloudflare site appears again). Once a legitimate browser sends the response to the challenge, cloudflare can set a cookie and then reloads the site. During that second request a legitimate browser now sends cloudflares cookie. This can be used as a powerful signal when deciding whether or not a request is forwarded to the backend server.