A Poem on GitHub Secretly Steered Malware That Hijacked More Than 3,400 Exposed AI Servers to Mine Crypto
PoeLLM malware infected more than 3,400 exposed AI servers running tools like LiteLLM and Ollama, mined crypto on their GPUs and found its command servers by decoding words in a poem stored on GitHub.

Since April, malware has been breaking into exposed AI servers, putting their GPUs to work mining cryptocurrency, and taking its orders from a poem. More than 3,400 machines were hit, mostly in the US and Western Europe.
Lumen's Black Lotus Labs calls the malware PoeLLM and the campaign Canto Incognito. Researchers first spotted it in June while probing an Ivanti Sentry flaw, CVE-2026-10520, The Register reports.
Who got hit
Most victims ran open-source AI services left open to the internet with known bugs, such as LiteLLM and Ollama. Hundreds more ran the Gotenberg PDF converter or the Gitea developer platform, and Ivanti Sentry appliances were hit too.
LiteLLM keeps turning up in these stories. Attackers have exploited its MCP layer before, and PoeLLM went after it again. In one sample, it hit a LiteLLM MCP test endpoint tied to command injection bug CVE-2026-42271, which Horizon.ai researchers say can be chained with CVE-2026-48710 for unauthenticated remote code execution, BleepingComputer reports.
The address hidden in verse
The clever part is how PoeLLM finds its command server. It reads a poem titled "On the Nature of Connection", tucked into a file called dash.css in a GitHub repo. The account, ejejejdfbbebe, had forked the source of the nodejs.org site and made its first commit on 13 April.
The malware pulls four words from fixed spots in the verse and turns each into a number using a dictionary built into its code. In one version, "driver", "diode", "decryption" and "string" became 92, 119, 165 and 74, which gives the IP address 92.119.165.74, CyberScoop reports.
To move to a new server, the operator just edits the poem. It was edited 11 times.
"To anyone who comes across it, this is simply a poem on GitHub," said Ryan English of Black Lotus Labs. "It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models." Many of the command servers were never flagged on crowd-sourced security tools.
What the malware did once inside
AI servers come with powerful GPUs, and PoeLLM put them to use. It ran XMRig and Iron miners tied to the Russian mining service Kryptex and opened a remote shell for the operator.
Each victim also became a recruiter. Infected machines scanned for ports 3000 and 4000, the defaults for Gotenberg and LiteLLM, and launched exploits at whatever they found. Several of its command servers appear to have been hijacked routers themselves.
The campaign peaked in mid-June with almost 2,200 affected servers and nearly 800 active each day, The Hacker News reports. Recent SSH and login-portal traffic hints that the operator had started experimenting with brute-force attacks. The actor "has effectively created a private army of AI-enabled proxies," English said.
An Italian connection
Black Lotus Labs believes with moderate confidence that the operator speaks Italian and is based in Italy, pointing to Italian comments in the code and servers located there. The researchers also think the poem itself was written by AI.
The run is over for now. Black Lotus Labs null-routed the command servers and alerted GitHub, the repo is gone, and English told The Hacker News the campaign looks fully disrupted.
Some offers on this page may be paid placements or contain affiliate links.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free