Earlier quoted context omitted.
yes, " https://polyfill.archive.org/v3/polyfill.min.js?features=fet... " is the URL with the malicious code
It looks like it is running the service that was part of the supply chain attacker earlier this year. https://github.com/polyfillpolyfill/polyfill-service/issues/...
https://sourcegraph.com/github.com/polyfillpolyfill/polyfill...
Seems like they self hosted that service