I fail to see how this attack has anything to do with http? The scripts can be served over https no problem, it’s the host that is compromised. Maybe you’re thinking of sub-resource integrity attributes?
"Mitigations
These attacks would not be successful if the following resources were served over HTTPS instead of HTTP:
http://push.zhanzhang.baidu.com/push.js; orhttp://js.passport.qihucdn.com/11.0.1.js
You may want to consider blocking these URLs when not sent over HTTPS."
https://developer.mozilla.org/en-US/docs/Web/Security/Same-o...