Tor security advisory: exit relays running sslstrip in May and June 2020
blog.torproject.org
blog.torproject.org
And it really is. In essence, a man in the middle converts all https links to http and proxies out the traffic. A victim would need to notice the missing https in the the url to detect this.
HSTS and https-everywhere browser plugin partially solves the problem.
I think the only viable solution is for all http traffic to be encrypted and to consider non-encrypted traffic suspect.