Description
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL.

The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.

The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.

The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation.

For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12.

For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem.

The SHA-256 digests of the files are

fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz
27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12

9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz
27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Immediate Investigation
AI Analysis

Impact

The Crypt::SelfCertificate Perl module, versions 1.01 through 1.05, contains embedded malware that executes a Python script downloaded from a hard‑coded HTTP URL. The URL is obfuscated via base64 encoding, and the script is run as the current user without being written to disk. This allows arbitrary code execution with the privileges of the user running the module, presenting a severe compromise risk. The vulnerability is a form of malware delivery and execution, categorized under CWE-506.

Affected Systems

The affected product is the Crypt::SelfCertificate module for the Perl programming language, distributed through CPAN. Versions 1.01 through 1.05 (inclusive) are impacted, with malicious payload files located in lib/Crypt/SelfCertificate/sample/validate.p12 for version 1.01 and lib/Crypt/SelfCertificate/sample/cert7.pem for version 1.05. Systems that have installed any of these versions from the provided tarballs are at risk.

Risk and Exploitability

Because the payload is launched when the generate_certificate function is called, any user invoking this function—directly from a Perl script or indirectly within an application—can trigger the remote code download and execution. No additional privileges or network exposure beyond the hard‑coded HTTP request are necessary. The CVSS score for the vulnerability is 7.8, indicating a high level of severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the absence of a patch and the nature of the threat make the risk high. Investigators should consider the environment potentially compromised immediately upon installation of the affected package.

Generated by OpenCVE AI on September 22, 2026 at 22:37 UTC.

Remediation

Vendor Solution

Systems on which the affected package was installed should be considered potentially compromised and investigated accordingly.


OpenCVE Recommended Actions

  • Remove or upgrade any installed Crypt::SelfCertificate 1.01–1.05 packages and replace them with a verified, non‑malicious version from CPAN or the vendor site.
  • Scan the system for the specific sample files validate.p12 and cert7.pem and any remaining malicious artifacts that may have been loaded during installation or execution.
  • Perform a thorough malware analysis and review logs for evidence of the obfuscated URL request and remote code execution, and investigate any compromised accounts or processes.

Generated by OpenCVE AI on September 22, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
References

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12. For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem. The SHA-256 digests of the files are fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem
Title Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
Weaknesses CWE-506
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-09-23T03:09:27.839Z

Reserved: 2026-09-22T16:29:23.694Z

Link: CVE-2026-95831

cve-icon Vulnrichment

Updated: 2026-09-22T20:07:28.210Z

cve-icon NVD

Status : Deferred

Published: 2026-09-22T19:17:00.227

Modified: 2026-09-23T03:17:05.090

Link: CVE-2026-95831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:45:17Z

Weaknesses