I think one of the main reasons it is done via hotlinking is that it is easier for the „webmaster“ to copy a JS snippet than to do something server side or self host. Most of these webmasters aren‘t developers.
This is particularly true for anything that comes as a „module“, like GDPR cookie notices (that are very frequently included via a JS snippet loaded from a third party site).
This is particularly true for anything that comes as a „module“, like GDPR cookie notices (that are very frequently included via a JS snippet loaded from a third party site).