Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure
PoeLLM malware uses a GitHub poem to derive C2 addresses and mine cryptocurrency on more than 3,400 exposed AI servers.
Lumen’s Black Lotus Labs says PoeLLM, active since at least April 2026, has compromised more than 3,400 servers, mostly in the United States and Western Europe. The malware reads four marked words from a poem in a GitHub repository and maps them to the current command-and-control IPv4 address, so operators can rotate infrastructure by editing the poem. It targets exposed LiteLLM, Ollama, Gotenberg, and Gitea services; one LiteLLM path is linked to command-injection flaw CVE-2026-42271. The Linux payload provides a remote shell, scanning, exploit delivery, and XMRig and Iron miners that contact Kryptex.