Trojanized Perl CPAN distributions Crypt::SelfCertificate 1.01–1.05 (CVE-2026-95831) and IO::Socket::SSL::SelfCertificate 1.00 (CVE-2026-97230) executed Python code fetched from…
Two Perl CPAN packages — Crypt::SelfCertificate 1.01–1.05 (CVE-2026-95831) and IO::Socket::SSL::SelfCertificate 1.00 (CVE-2026-97230) — shipped malware that runs Python code retrieved from an obfuscated URL; the affected Crypt::SelfCertificate releases were…
Robert Rothenberg disclosed on oss-security on 2026-09-22 that the Perl distribution Crypt::SelfCertificate, versions 1.01 through 1.05 on CPAN, contains malware that executes Python code retrieved from an obfuscated URL, tracked as CVE-2026-95831. Follow-up discussion on 2026-09-23 noted that the distribution's MetaCPAN requirement and changelog pages were not loading, which a poster attributed to the distribution having been yanked, and asked whether the module ever had a legitimate release. In a reply the same day, Rothenberg stated that every affected version had been removed, although copies may remain on independent mirrors, and that no reverse dependencies are known. He added that version 1.00 did not include the dropper but did not work properly and may have served as staging so that an upgrade would install the malware; CPANSec is still investigating. This partially answers the earlier question: a 1.00 release existed, but it is described as non-functional and dropper-free rather than as a confirmed clean release. On 2026-09-24, Rothenberg reported a second malicious distribution, IO::Socket::SSL::SelfCertificate version 1.00 (CVE-2026-97230), listed on MetaCPAN and exhibiting the same behavior of executing Python code fetched from an obfuscated URL; that post does not describe confirmed compromise of downstream users. Sources are consistent; no disagreements were identified across the reports.
- CVE-2026-95831 covers Crypt::SelfCertificate versions 1.01 through 1.05 on CPAN; the malware executes Python code fetched from an obfuscated URL.
- CVE-2026-97230 covers IO::Socket::SSL::SelfCertificate version 1.00 for Perl, which exhibits the same behavior of executing Python code from an obfuscated URL.
- Both vulnerabilities were reported to oss-security by Robert Rothenberg, on 2026-09-22 and 2026-09-24 respectively.
- All affected Crypt::SelfCertificate versions have been removed from CPAN, though copies may remain on independent mirrors.
- No reverse dependencies on Crypt::SelfCertificate are currently known.
- Crypt::SelfCertificate 1.00 did not include the dropper but did not work properly and may have served as staging so that an upgrade would install the malware.
- CPANSec is still investigating; the IO::Socket::SSL::SelfCertificate report does not describe confirmed compromise of downstream users.
Coverage timelineoldest first · each row is one article
- · 4d agoCVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
oss-security· 66
Crypt::SelfCertificate 1.01–1.05 for Perl contains malware that runs Python from an obfuscated URL.
- · 4d agoRe: CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
oss-security· 58
CVE-2026-95831: malicious Crypt::SelfCertificate 1.01–1.05 runs Python from an obfuscated URL.
- · 3d ago
Vulnerabilities in this storyAll →
- CVE-2026-958317.8—Embedded Malware in Perl CPAN Module Crypt::SelfCertificate 1.01–1.05published · CPAN (Perl distribution, author unattributed in advisory) Crypt::SelfCertificate
- CVE-2026-972309.8—Malicious Remote Code Execution in Perl Module IO::Socket::SSL::SelfCertificate 1.00published · IO::Socket::SSL::SelfCertificate (Perl module)
| CVE | Vulnerability |
|---|