Menu
BREAKING NEWS

PoeLLM Malware Uses GitHub Poem to Control AI Server Botnet

Uday Patil Oct 8, 2026 10 min read 9 views
PoeLLM Malware Uses GitHub Poem to Control AI Server Botnet

PoeLLM malware is targeting exposed AI and open-source infrastructure while using an unusual GitHub-hosted poem to determine where infected systems should connect for command-and-control instructions.

Researchers at Lumen Technologies’ Black Lotus Labs identified the malware as part of a financially motivated campaign they call Canto Incognito. The operation has been active since at least April 2026 and primarily targets internet-facing deployments of LiteLLM, Ollama, Gotenberg and Gitea.

Instead of embedding a fixed command-and-control address directly in the malware, PoeLLM extracts selected words from a poem stored on GitHub and converts those words into an IP address using a hard-coded dictionary.

This allows the attacker to move the malware’s control infrastructure simply by editing a few words in the poem without rebuilding or redistributing the malware.

For broader coverage of attacks targeting AI infrastructure and emerging AI-related threats, see our AI-Era Threats and Agentic Security Guide.

Key takeaway: PoeLLM turns exposed AI and open-source servers into cryptocurrency miners, scanners and exploit workers while using an ordinary-looking GitHub poem as a resilient method for locating its command-and-control infrastructure.

What Is PoeLLM Malware?

PoeLLM is Linux malware observed in an active cryptomining and botnet-expansion campaign.

Black Lotus Labs says the malware primarily affects vulnerable internet-facing services, including:

  • LiteLLM
  • Ollama
  • Gotenberg
  • Gitea

Researchers also observed activity involving Ivanti Sentry infrastructure during the investigation, although not every exposed product was necessarily compromised through the same vulnerability.

Once a system is infected, PoeLLM can provide remote-shell functionality, scan the internet for additional vulnerable systems, deliver exploits and deploy cryptocurrency miners.

GitHub Poem Acts as PoeLLM’s C2 Address Book

The most distinctive part of the campaign is its GitHub poem C2 mechanism.

The threat actor placed a poem titled On the Nature of Connection inside a file called dash.css in a GitHub repository.

The repository is a fork of the Node.js website source code, but researchers found no connection between the malware campaign and the legitimate Node.js project.

PoeLLM retrieves the poem and looks for four specific words or phrases at predetermined locations.

A dictionary embedded in the malware maps each selected word to a number.

The four numbers are then combined to produce an IPv4 address that the malware uses as its current command-and-control server.

How the Poem Generates a C2 Server

Black Lotus Labs documented an example in which four words from the poem translated into four numerical values.

Those values became the four octets of an IP address.

The important part is not the individual words themselves but the technique.

If defenders block the current command server, the operator can edit selected words in the GitHub poem.

Infected machines that retrieve the updated file then calculate a different C2 address automatically.

This means the attacker does not need to modify or redeploy the malware simply to rotate infrastructure.

The Poem Has Been Updated Repeatedly

Black Lotus Labs says the first known GitHub commit containing the poem was made on April 13, 2026.

Researchers observed 11 updates to the poem after the initial commit while the decoding mechanism remained unchanged.

That makes the GitHub page function like a lightweight, externally editable directory for the malware’s infrastructure.

The approach is also difficult to identify through simple static filtering because the repository contains ordinary text rather than an obvious list of malicious IP addresses.

More Than 3,400 Servers Identified in the Campaign

Lumen’s current overview reports more than 3,400 affected servers, with most observed victims located in the United States and Western Europe.

Some sections of reporting around the campaign reference an earlier count of nearly 2,200 systems, so the higher 3,400-plus figure should be understood as the more recent overall estimate rather than a completely separate victim set.

The campaign continues to infect new systems, according to Black Lotus Labs.

Exposed AI Infrastructure Is a Major Target

PoeLLM is particularly notable because many of its targets are systems used to support AI and large language model workloads.

LiteLLM can act as a gateway for multiple LLM providers, while Ollama is widely used to run language models locally or on servers.

If these services are exposed directly to the internet with vulnerable configurations or outdated software, attackers may gain access to valuable compute resources.

AI servers are especially attractive to cryptomining operators because they may have powerful CPUs or GPUs capable of generating significantly more mining revenue than ordinary endpoints.

LiteLLM Exploitation Linked to CVE-2026-42271

Black Lotus Labs observed exploitation activity involving a LiteLLM endpoint associated with CVE-2026-42271.

The vulnerability involves command injection and can allow attackers to execute commands against vulnerable LiteLLM deployments under applicable conditions.

Researchers observed crafted POST requests targeting the /mcp-rest/test/connection endpoint and directing vulnerable systems to retrieve attacker-controlled payloads.

This is an important distinction: the GitHub poem is used to locate PoeLLM’s command infrastructure, while exploitation of vulnerable services is how attackers can initially compromise exposed systems.

Infected Servers Help Find the Next Victim

PoeLLM does more than install a cryptocurrency miner.

Compromised servers are reused as scanning and exploitation nodes.

This allows the attacker to distribute reconnaissance and exploitation activity across already compromised infrastructure rather than operating everything from a small number of dedicated servers.

Black Lotus Labs observed broader scanning beginning in May 2026, particularly against ports associated with LiteLLM and Gotenberg.

This creates a self-expanding botnet model:

  1. A vulnerable internet-facing service is compromised.
  2. PoeLLM is installed.
  3. The infected system connects to the current C2 server.
  4. Cryptocurrency mining begins.
  5. The victim is also used to scan for additional exposed systems.
  6. New vulnerable servers receive exploitation attempts.
Campaign overview (Source – Canto)

PoeLLM Deploys Cryptocurrency Miners

The malware has been observed deploying cryptocurrency-mining tools including XMRig and Iron.

Researchers also observed infected hosts connecting to infrastructure associated with Kryptex, a cryptocurrency mining service.

This supports Black Lotus Labs’ assessment that the campaign is financially motivated rather than focused primarily on espionage or destructive operations.

Remote Shell and Exploitation Capabilities

The analyzed Linux ELF payload provides capabilities beyond cryptomining.

According to Black Lotus Labs, PoeLLM can support:

  • Remote shell access
  • HTTP and HTTPS scanning
  • Exploit delivery
  • Cryptocurrency mining
  • Botnet expansion

Researchers also saw traffic involving SSH and other login services, suggesting that the operator experimented with distributed password-guessing activity.

However, the maturity and effectiveness of that capability were not conclusively established.

Who Is Behind PoeLLM?

Black Lotus Labs assesses that the campaign is associated with an Italian-speaking threat actor.

That assessment is based on indicators such as Italian-language comments in code and infrastructure evidence.

This does not constitute confirmed attribution to a named individual or threat group.

The safest description is therefore an Italian-speaking operator or actor rather than a known organization.

Compromised Routers May Support the Infrastructure

Researchers found evidence suggesting that the campaign may also use compromised home and office routers as part of its command infrastructure.

Several observed control servers exposed vulnerable router administration interfaces.

Black Lotus Labs suspects that some of these devices were reused as infrastructure, although researchers did not establish direct exploitation evidence for every router involved.

This approach can make takedown and attribution more difficult because malicious traffic appears to originate from ordinary residential or business networks.

Why the GitHub Technique Is Effective

Using GitHub provides several operational advantages to an attacker.

  • GitHub is widely trusted and rarely blocked outright.
  • The repository contains harmless-looking text rather than obvious malware configuration data.
  • The attacker can update the C2 destination without rebuilding the malware.
  • Infected systems can obtain new infrastructure information through normal HTTPS traffic.
  • Defenders cannot rely solely on extracting a fixed C2 IP from the malware sample.

This does not mean GitHub itself was compromised.

The attacker simply abused a public repository as an external configuration mechanism.

What Organizations Should Check

Organizations running internet-facing AI services should review whether those systems actually need to be publicly accessible.

Security teams should particularly inventory deployments of LiteLLM, Ollama, Gotenberg and Gitea and verify that security updates have been applied.

Useful defensive actions include:

  • Restrict public access to AI and development services.
  • Patch known vulnerabilities promptly.
  • Review logs for unusual outbound C2 connections.
  • Monitor unexpected cryptocurrency-mining activity.
  • Investigate unusual CPU or GPU utilization.
  • Review outbound connections from AI servers.
  • Block known malicious infrastructure where appropriate.
  • Segment AI infrastructure from sensitive production networks.
  • Review exposed edge devices and routers.

Gotenberg Should Not Be Directly Exposed

Gotenberg’s own deployment guidance warns against directly exposing the service to the public internet without appropriate protections.

The PoeLLM campaign reinforces why internal utility services should not automatically be reachable from the internet simply because they use common web ports.

Reverse proxies, authentication controls, network filtering and private access mechanisms can significantly reduce unnecessary exposure.

AI Servers Are Becoming Valuable Attack Targets

The campaign illustrates a broader shift in attacker priorities.

AI infrastructure is not only valuable because of the models or data it may contain.

It also provides high-performance compute resources, access tokens, API credentials and network connectivity that can be monetized or reused for additional attacks.

A server originally deployed to support AI experimentation can therefore become an attractive target for cryptomining, credential theft, scanning or lateral movement.

Frequently Asked Questions

What is PoeLLM malware?

PoeLLM is Linux malware used in a cryptomining and botnet-expansion campaign targeting exposed AI, LLM and open-source infrastructure.

Why is PoeLLM called PoeLLM?

The name reflects its unusual use of a poem hosted on GitHub to derive the command-and-control server used by infected systems.

Does the GitHub poem contain a malicious executable?

No. The poem acts as configuration data. PoeLLM extracts selected words from it and converts them into numbers that form the current C2 IP address.

Which services are being targeted?

Researchers observed activity involving LiteLLM, Ollama, Gotenberg and Gitea, along with possible targeting involving Ivanti Sentry.

How many servers have been affected?

Lumen Black Lotus Labs currently reports more than 3,400 affected servers across the campaign, with many located in the United States and Western Europe.

Does PoeLLM exploit GitHub?

No. The campaign abuses a public GitHub repository as a way to publish information used to calculate its current command-and-control address.

What does PoeLLM do after infection?

It can deploy cryptocurrency miners, provide remote-shell access, scan for additional vulnerable systems and help deliver exploits to expand the botnet.

Is Node.js compromised?

No evidence indicates that the legitimate Node.js project is involved. The attacker used a fork of the Node.js website repository as a place to host the poem.

Final Takeaway

PoeLLM malware demonstrates how attackers can combine traditional server exploitation with unconventional infrastructure techniques.

The GitHub-hosted poem does not infect systems by itself. Instead, it acts as a flexible address book that allows already compromised machines to determine where the attacker’s current command infrastructure is located.

The larger security issue is the continued exposure of AI and development services directly to the internet.

Organizations deploying LiteLLM, Ollama and similar infrastructure should treat those systems as production assets, restrict unnecessary external access and keep them continuously patched and monitored.

Stay Updated on AI Infrastructure Threats

Attackers are increasingly targeting AI infrastructure for compute resources, credentials and access to enterprise environments.

Follow CyberUpdates365 for verified cybersecurity news, malware research, AI security threats, vulnerability analysis and practical defense guidance.

Primary Source

Lumen Black Lotus Labs:
Canto Incognito: Tracking the PoeLLM Malware

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.