ISP's intercepting HTTP traffic to modify it is far from unheard of.
In the best case, this is to notify customers of required changes.
This is actually used by comcast [1].
In the worst case, this is a service sold to advertisers, or a service that includes arbitrary java-script injection. For something close to the worst case, see [2] (previously discussed on HN [3]).