Executive brief
Crypt::SelfCertificate is a Perl module for generating X.509 certificates. Versions 1.01 through 1.05 contain malicious code that downloads and executes arbitrary Python payloads from a remote server when the generate_certificate function is called. An attacker can gain complete control of systems running vulnerable versions, potentially leading to data theft, malware installation, or system compromise.
Technical details
The module contains embedded Python scripts in certificate files (validate.p12 in 1.01, cert7.pem in 1.05) that execute during certificate generation. These scripts fetch obfuscated code from http://144.172.104.211/settings/privacy.php and execute it directly without validation. Attack vector is local execution when generate_certificate() is called; no authentication or network connectivity from the victim is required beyond reaching the attacker's server.
Affected products
- CPAN Crypt::SelfCertificate 1.01 through 1.05
Timeline
- 2026-09-22: disclosed: CPANSec identified malware in versions 1.01 and later; module removed from CPAN