My brother ran into this while car shopping on a reputable Utah based Toyota dealership's website. It was a powershell script that downloaded and executed something from a base64 encoded Bitly URL. Bitly took down the URL so we couldn't see where it was redirecting.
It seems like attackers are embedding this in vulnerable legit websites
This reads like someone who has a base level understanding of how a chromebook works in an educational environment. Also reads like someone (I'm assuming American) who doesn't know what CIPA is.