Re: CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
CPAN removed Crypt::SelfCertificate 1.01–1.05 after CVE-2026-95831 identified a Python dropper.
CVE-2026-95831 covers Crypt::SelfCertificate versions 1.01 through 1.05 on CPAN, which contain malware that executes Python code retrieved from an obfuscated URL. Robert Rothenberg said every affected version has been removed, although copies may remain on independent mirrors, and that no reverse dependencies are known. Version 1.00 did not include the dropper but did not work properly and may have served as staging for an upgrade. CPANSec is still investigating.