Disable TLS Certificate Verification

discovered 2026-07-19

The dropper sets http.verify_mode = OpenSSL::SSL::VERIFY_NONE when fetching the payload, disabling TLS certificate validation so the download succeeds through interception, self-signed, or misconfigured TLS without warnings.

Seen in packages