Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure
PoeLLM malware uses a GitHub poem to derive C2 addresses and mine cryptocurrency on more than 3,400 exposed AI servers.
Lumen’s Black Lotus Labs says PoeLLM, active since at least April 2026, has compromised more than 3,400 servers, mostly in the United States and Western Europe. The malware reads four marked words from a poem in a GitHub repository and maps them to the current command-and-control IPv4 address, so operators can rotate infrastructure by editing the poem. It targets exposed LiteLLM, Ollama, Gotenberg, and Gitea services; one LiteLLM path is linked to command-injection flaw CVE-2026-42271. The Linux payload provides a remote shell, scanning, exploit delivery, and XMRig and Iron miners that contact Kryptex.
- PoeLLM maps four poem words from GitHub to its current C2 IPv4 address.
- More than 3,400 servers were affected, mainly in the US and Western Europe.
- Linux payload adds a remote shell, scanning, exploits, and XMRig and Iron miners.
- One LiteLLM attack path is linked to command injection CVE-2026-42271.
- Black Lotus Labs says the campaign has been active since at least April 2026.
Vulnerabilities mentionedAll →
- CVE-2026-422718.793%Command Injection in BerriAI LiteLLM AI Gateway Exploited in the Wildpublished · BerriAI LiteLLM (proxy server / AI Gateway) KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-42271 | Command Injection in BerriAI LiteLLM AI Gateway Exploited in the Wild CVE-2026-42271 is a command injection (CWE-77/CWE-78) in BerriAI LiteLLM's proxy server, a widely used AI gateway for calling LLM APIs. Two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) accept a full stdio server configuration, including command, args, and env fields, and spawn the supplied command as a subprocess on the proxy host; the endpoints are gated only by any valid proxy API key with no role check, so even low-privilege internal-user keys can trigger it. An attacker with any authenticated key gains arbitrary command execution with the privileges of the proxy process, and reporting indicates attackers are chaining the flaw into broader takeover of AI gateway servers, including reverse shells and crypto miners, in some cases via weak or default keys such as the example 'sk-1234' admin key. Any organization running LiteLLM versions 1.74.2 through before 1.83.7, including LiteLLM distributed with Red Hat OpenShift AI, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-08 and is under active attack, with a very high EPSS of 83.6% for exploitation within 30 days. |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | edge-ru-07.kryptex.network | Mining endpoint 46.21.245[.]211:7029 Kryptex Mining domain edge-ru-07[.]kryptex[.]network Pool host Mining domain Kryptex[.]ru Pool service Paylo |
| domain | kryptex.ru | main edge-ru-07[.]kryptex[.]network Pool host Mining domain Kryptex[.]ru Pool service Payload URL hxxp://5.78.73[.]122:81/private/ |
| domain | malwarescan.xyz | 5[.]211:80 Initial infrastructure contact Associated domain malwarescan[.]xyz Possible operator service Mining endpoint 5.180.174[.]162 |
| sha256 | 6fab94577364beec314afae3b082dd680933f08a8349b9f35b92667e8231b501 | ators of compromise (IoCs):- Type Indicator Context SHA-256 6fab94577364beec314afae3b082dd680933f08a8349b9f35b92667e8231b501 Reviewed sample C2 92.119.164[.]50 Active C2 103.249.201[.] |
| url | http://5.78.73[ | ol host Mining domain Kryptex[.]ru Pool service Payload URL hxxp://5.78.73[.]122:81/private/python3.6 Download Payload URL hxxp://5.78. |
Full article735 words · extracted from cybersecuritynews.com · click to collapse
Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet.
The campaign targets internet-facing services, including LiteLLM and Ollama, while also affecting Gotenberg PDF converters and Gitea development servers.
Active since at least April 2026, PoeLLM uses selected words in the poem to calculate its next control server address. Changing those words lets the attacker redirect infected machines without replacing the malware.
Compromised servers also become scanners and exploit workers, helping the operation reach more victims. Researchers from Lumen’s Black Lotus Labs identified the malware while investigating activity linked to an Ivanti Sentry vulnerability in June.
Their technical report, published October 7, describes more than 3,400 affected servers in its overview, although sections retain an earlier figure of almost 2,200. Most victims were in the United States and Western Europe.
Hackers Use GitHub-Hosted Poem
The attacker placed a poem titled “On the Nature of Connection” inside a file in a GitHub repository forked from the Node.js website source code. Researchers found no apparent connection between the malware and the legitimate Node.js project.
PoeLLM extracts four words or phrases using fixed text markers. A dictionary stored inside the malware maps each extracted value to a number. Together, those four numbers form the IPv4 address of the current command-and-control server.
.webp)
One example maps “driver,” “diode,” “decryption,” and “string” to four address components. Researchers observed 11 poem updates after the initial April 13 commit, while the decoding pattern stayed unchanged.
This makes rotation simple: the operator changes selected words, and infected systems calculate the replacement address.
Exposed AI Services Fuel Botnet Growth
Broader scanning began in May, with traffic focused on ports associated with Gotenberg and LiteLLM. Crafted POST requests instructed vulnerable systems to download payloads from the attacker’s infrastructure.
Researchers linked one likely LiteLLM attack path to command injection vulnerability CVE-2026-42271, previously covered in LiteLLM exploitation reporting.
The Linux ELF payload combines remote-shell access, HTTP/S scanning, exploit delivery, and XMRig and Iron cryptocurrency miners.
Infected machines contacted Kryptex mining services and supplied additional workers for the botnet. The same exposure problem appears in earlier coverage of publicly accessible Ollama servers.
Researchers also observed traffic toward SSH and other login portals, suggesting experiments with distributed password guessing. They could not establish how mature that capability was.
Italian-language code comments and network evidence suggest an Italian-speaking operator, not a confirmed identity. Several control servers exposed vulnerable router administration pages.
Researchers suspect the attacker reused compromised routers, but found no direct exploitation evidence for the first router’s two identified vulnerabilities.
Lumen recommends reviewing network logs, limiting public access, and including AI tools in regular patching and exposure checks. Gotenberg’s installation guidance warns against direct internet exposure. Routers, firewalls, and other edge devices also require timely updates.
PoeLLM demonstrates direct server exploitation rather than a proven package compromise or stolen-model-access scheme.
Related coverage of the LiteLLM supply-chain compromise and LLMjacking through leaked AWS credentials shows other routes into AI environments; those incidents should not be confused with this campaign.
Indicators of compromise (IoCs):-
| Type | Indicator | Context |
|---|---|---|
| SHA-256 | 6fab94577364beec314afae3b082dd680933f08a8349b9f35b92667e8231b501 | Reviewed sample |
| C2 | 92.119.164[.]50 | Active |
| C2 | 103.249.201[.]108 | Active |
| C2 | 178.128.14[.]204 | Active |
| C2 | 191.37.28[.]160 | Historical |
| C2 | 89.39.253[.]46 | Historical |
| C2 | 120.224.114[.]212 | Historical |
| C2 | 5.78.73[.]122 | Historical |
| C2 | 15.204.178[.]28 | Historical |
| C2 | 92.119.165[.]74 | Historical |
| C2 | 45.133.73[.]28 | Historical |
| C2 | 185.132.53[.]158 | Historical |
| C2 | 136.148.69[.]233 | Historical |
| Suspected administration | 185.119.19[.]171 | Moderate-confidence assessment |
| Associated server | 57.131.5[.]211:80 | Initial infrastructure contact |
| Associated domain | malwarescan[.]xyz | Possible operator service |
| Mining endpoint | 5.180.174[.]162:8029 | Kryptex |
| Mining endpoint | 46.21.245[.]211:7029 | Kryptex |
| Mining domain | edge-ru-07[.]kryptex[.]network | Pool host |
| Mining domain | Kryptex[.]ru | Pool service |
| Payload URL | hxxp://5.78.73[.]122:81/private/python3.6 | Download |
| Payload URL | hxxp://5.78.73[.]122:81/private/bins.sh | Download |
| File | libgcrypt | Malware filename |
| GitHub account | ejejejdfbbebe | Poem publisher |
| Repository file | dash.css | Poem storage |
| Target endpoint | /mcp-rest/test/connection | Likely exploitation path |
| C2 ports | 3778, 5001, 5002, 9999 | Beacon traffic |
| Other ports | 81; 3000, 4000; 2222 | Downloads; scanning; router interface |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.