I hope this drives home the need to stop including 3rd party javascript on websites. It makes visitors' browsers load and run code of variable trustworthiness. The browser sandbox is entirely ill-equipped to keep users safe and secure online or prevent their computers from being leveraged for malicious ends. The sandbox allows everything but the most indefensible exploitative actions.
HTTPS is great and all, and does change the threat model but the Chinese government controls root certificates your browser trusts. And they weren't worried about getting detected funneling traffic to github.