The alert for CVE-2026-97230 identifies the Perl distribution IO-Socket-SSL-SelfCertificate and flags version 1.00 as compromised. According to the text, the malware runs Python code fetched from an obfuscated URL. The notice was published on September 24, 2026, and is described as an automatic translation of content from the oss-sec feed.
If your organization uses this module, check your dependency inventory for version 1.00. Do not infer the full scope of the compromise or the complete behavior of the malicious code from this summary alone.
To confirm the alert and check for updates, look up CVE-2026-97230 in the oss-sec feed and compare it with the distribution records on MetaCPAN. The news item cites both as sources; consult the original records, not only the automatic translation.
When using AI to review the notice or dependency files, avoid submitting personal data, credentials, proprietary code, or internal details. If sensitive material must be studied, apply your organization’s policy and use minimized data or placeholder markers.