It's still not common. I assume a zombie computer somewhere was trying to connect to a Command&Control server via Tor - a C&C which is being sinkholed by anti-malware researchers or is otherwise flagged. So your exit machine looks as if it is infected.
It's likely that the malware just uses the system's default proxy to connect, and is not specifically looking to use Tor.