Not sure about MITM, no proof against it but seems hardly likely.
It might have been some weird attempt to reduce latency. Wireshark seemed to show responses that were sent before the request that triggered it had finished transmitting. The handshake seemed really shuffled out of order. Watching curl do the handshake sent far fewer bytes.