PoeLLM malware infects exposed AI servers in cryptomining attacks
PoeLLM cryptomining malware has compromised over 2,100 exposed AI servers, using GitHub poems for command-and-control.
Lumen's Black Lotus Labs says PoeLLM has compromised more than 2,100 servers, with as many as 800 infections active in one day, mainly in the United States and Western Europe. Active since at least April 2026, the Linux malware derives its command-and-control IPv4 address from keywords in a GitHub-hosted poem and has used at least 11 controllers. Compromised hosts scan, deploy exploits, open a remote shell, and run XMRig and Iron miners associated with the Russian service Kryptex. Targets include exposed LiteLLM, Ollama, Gotenberg, and Gitea; CVE-2026-42271 can be chained with CVE-2026-48710 for unauthenticated LiteLLM remote code execution. Researchers moderately assess the operator as Italian.