Add a hidden service to check.torproject.org
TorBrowser gets it's version information from https://check.torproject.org/RecommendedTBBVersions and https://check.torproject.org/ is TBB's homepage.
For an adversary, it's granted, that every user of Tor Browser will visit that page. It must be too tempting to MITM that site and to spread some malicious content.
The SSL certificate authority system was recently compromised and is flawed by design. I suggest making check.torproject.org accessible through a hidden service.