CVE-2026-97230: IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL
Malicious Perl package IO::Socket::SSL::SelfCertificate 1.00 (CVE-2026-97230) executes Python from an obfuscated URL.
Robert Rothenberg reported that IO::Socket::SSL::SelfCertificate version 1.00 for Perl contains malware, tracked as CVE-2026-97230. The package executes Python code retrieved from an obfuscated URL. The distribution is listed on MetaCPAN. The oss-security post does not describe confirmed compromise of downstream users.