Critical PoeLLM Malware Targets AI Infrastructure Via GitHub Poem
Key Takeaways A novel malware, PoeLLM, is actively targeting internet-facing AI infrastructure and development servers. The malware employs a unique command-and-control (C2) mechanism, embedding C2...
Key Takeaways
- A novel malware, PoeLLM, is actively targeting internet-facing AI infrastructure and development servers.
- The malware employs a unique command-and-control (C2) mechanism, embedding C2 server addresses within a poem hosted on GitHub.
- Affected systems, including LiteLLM, Ollama, Gotenberg PDF converters, and Gitea servers, are converted into cryptocurrency mining botnet nodes and participate in further scanning and exploitation.
- Over 3,400 servers globally have been compromised since April 2026, primarily in the United States and Western Europe.
- Defenders should prioritize patching, limit public exposure of AI services, and implement robust network monitoring.
A sophisticated malware campaign, dubbed PoeLLM, is leveraging a poem published on GitHub to dynamically direct its command-and-control (C2) infrastructure. This innovative approach allows attackers to transform vulnerable internet-facing AI services and development platforms into a burgeoning cryptocurrency-mining botnet.
Table Of Content
The operation specifically targets publicly accessible services like LiteLLM and Ollama, alongside Gotenberg PDF converters and Gitea development servers. This widespread targeting highlights a broad assault on critical components within modern software development and AI deployment pipelines.
First detected in April 2026, PoeLLM distinguishes itself by encoding its C2 server addresses within specific words of a GitHub-hosted poem. This method grants the attackers significant agility, enabling them to alter the C2 address simply by modifying the poem, obviating the need to update the malware itself on compromised machines. Beyond cryptocurrency mining, infected servers are repurposed as scanners and exploit delivery platforms, expanding the botnet’s reach.
Researchers from Lumen’s Black Lotus Labs identified this malware activity in June while investigating an unrelated Ivanti Sentry vulnerability. Their detailed technical report, released on October 7, documents over 3,400 compromised servers, though some sections of the report reference an earlier count of approximately 2,200. The majority of these victims are located in the United States and Western Europe, indicating a focus on regions with significant AI and development infrastructure.
Hackers Use GitHub-Hosted Poem for Dynamic C2
The attacker’s ingenious C2 mechanism involves a poem titled “On the Nature of Connection,” embedded within a file in a GitHub repository. This repository was forked from the legitimate Node.js website source code, though researchers found no direct link between the malware and the Node.js project itself.
PoeLLM operates by extracting four specific words or phrases from the poem, guided by fixed text markers. An internal dictionary within the malware then maps each extracted value to a numerical component. These four numbers are subsequently combined to form the IPv4 address of the active C2 server.
For instance, phrases such as “driver,” “diode,” “decryption,” and “string” might translate into the numerical segments of an IP address. Since its initial commit on April 13, researchers have observed 11 updates to the poem, while the underlying decoding algorithm within the malware has remained constant. This design allows the operator to effortlessly rotate C2 servers by simply modifying a few words in the GitHub poem, with infected systems autonomously calculating the new address.
Exposed AI Services Fuel Botnet Growth
The campaign’s scanning activities intensified in May, with a clear focus on ports commonly associated with Gotenberg and LiteLLM services. Attackers send specially crafted POST requests to vulnerable systems, instructing them to download malicious payloads from the attacker’s infrastructure.
One identified attack vector for LiteLLM involves the command injection vulnerability CVE-2026-42271, which has been previously documented in relation to LiteLLM exploitation. The delivered Linux ELF payload is multifaceted, incorporating remote-shell capabilities, HTTP/S scanning functionality, exploit delivery mechanisms, and both XMRig and Iron cryptocurrency miners.
Compromised machines are observed communicating with Kryptex mining services, effectively augmenting the botnet’s mining power. A similar exposure vulnerability has been noted in previous reports concerning publicly accessible Ollama servers.
Beyond direct exploitation, researchers also detected traffic directed toward SSH and other login portals, suggesting the attackers are experimenting with distributed password guessing attacks. The full maturity of this capability, however, remains unconfirmed.
Evidence, including Italian-language code comments and network telemetry, points to an Italian-speaking operator, though a definitive identity has not been established. Furthermore, several C2 servers revealed vulnerable router administration pages, leading researchers to suspect that the attackers are recycling compromised routers. Despite this, direct exploitation evidence for the two identified vulnerabilities in the initial router could not be confirmed.
This PoeLLM campaign primarily relies on direct server exploitation, rather than exploiting compromised packages or stolen model access credentials. This contrasts with other recent incidents involving AI environments, such as the LiteLLM supply-chain compromise or LLMjacking attacks facilitated by leaked AWS credentials, which should not be conflated with this particular operation.
What You Should Do
- Review Network Logs: Proactively search for Indicators of Compromise (IoCs) provided below in your network logs and security information and event management (SIEM) systems.
- Limit Public Access: Restrict public exposure of AI tools like LiteLLM and Ollama, and development servers such as Gitea. Configure firewalls and network access controls to minimize their internet footprint. Gotenberg’s installation guidance explicitly warns against direct internet exposure.
- Patch and Update: Ensure all AI tools, development servers, routers, firewalls, and other edge devices are regularly patched and updated to the latest secure versions.
- Implement Strong Authentication: Use multi-factor authentication (MFA) for all administrative interfaces and services.
- Regular Exposure Checks: Incorporate AI tools into your regular vulnerability scanning and external exposure assessment processes.
Indicators of Compromise (IoCs):-
| Type | Indicator | Context |
|---|---|---|
| SHA-256 | 6fab94577364beec314afae3b082dd680933f08a8349b9f35b92667e8231b501 |
Reviewed sample |
| C2 | 92.119.164[.]50 |
Active |
| C2 | 103.249.201[.]108 |
Active |
| C2 | 178.128.14[.]204 |
Active |
| C2 | 191.37.28[.]160 |
Historical |
| C2 | 89.39.253[.]46 |
Historical |



No Comment! Be the first one.