✉ The Friday AI Brief: the week's 5 best AI stories, tools & comparisons — in your inbox every Friday morning.

Ollama logo

Meet PoeLLM: The Malware Hiding Its Orders in a GitHub Poem — and Mining Crypto on Exposed AI Servers

Meet PoeLLM: The Malware Hiding Its Orders in a GitHub Poem — and Mining Crypto on Exposed AI Servers

October 8, 2026.

Researchers at Lumen’s Black Lotus Labs have detailed a campaign, dubbed Canto Incognito, that has infected more than 3,400 exposed AI and developer servers with malware called PoeLLM — which hides its command-and-control addresses inside a poem posted to GitHub. The malware mines cryptocurrency and turns each compromised server into a scanner that hunts for the next victim. Why it matters: if you run AI tools like LiteLLM or Ollama exposed to the internet, this is a live, active threat against your GPU servers right now.

Key takeaway: PoeLLM targets internet-facing AI infrastructure — LiteLLM gateways, Ollama model runners, Gitea, Gotenberg, and Ivanti Sentry appliances — using a poem on GitHub as its command channel so the operator can rotate infrastructure by editing a few words. Patch your AI tools, take management APIs off the public internet, and assume any exposed server is already a target.

What happened

According to research published October 7, 2026, the Canto Incognito campaign has been active since at least April 2026 and has targeted systems primarily in the United States and Western Europe. The malware installs the XMRig and Iron cryptocurrency miners and connects victims to Kryptex, a Russian cryptocurrency mining service. At its peak, as many as 800 infected systems were active on a single day.

The compromised hosts are reused to expand the botnet: infected servers are turned into scanners and exploit launchpads, so each victim becomes infrastructure for attacking the next. The operator remains unidentified; Black Lotus Labs assessed with moderate confidence that the operator may be Italian, based on comments in the malware and an Italy-based server hosting an admin interface — but that is not a confirmed attribution.

How the poem trick works

PoeLLM — a Linux ELF file named libgcrypt — doesn’t hardcode its command-and-control address. Instead, it extracts four words from a poem the attackers wrote and hosted in a file called dash.css on a public GitHub repository, then maps those words to an IPv4 address through a hardcoded dictionary. Every time the operator wants to rotate infrastructure, they change a few words in the poem; the deployed malware needs no update. Researchers say the poem has been edited at least 11 times, yielding 12 identified control servers. A likely entry vector, per the research, is a LiteLLM endpoint tied to a known vulnerability affecting versions 1.74.2 through 1.83.6 — though how API keys were obtained remains unconfirmed.

Why it matters

This is the shape of the modern AI security problem: powerful GPU servers, spun up fast and exposed to the internet with management APIs that should never face the public web. PoeLLM’s tradecraft — hiding control infrastructure in plain sight on GitHub — is designed to outlast the usual blocklists. For anyone running AI services: restrict public internet exposure, patch LiteLLM/Ollama/Gitea/Gotenberg now, rebuild compromised systems rather than cleaning them, and rotate secrets. The researchers note that blocking known IPs alone will miss the control servers after each poem update — so network exposure controls and egress filtering matter more than lists.

Frequently asked questions

Is my ChatGPT or Claude account at risk?

No. This targets self-hosted, internet-exposed server software like LiteLLM and Ollama, not consumer AI accounts.

How many servers were infected?

The Hacker News, citing Lumen Black Lotus Labs, reports more than 3,400 servers compromised since April 2026, with up to 800 active at once at the peak.

What is Kryptex?

A Russian cryptocurrency mining service that the malware uses to convert stolen GPU time into mining revenue.

Who is behind it?

Unknown. Black Lotus Labs assessed with only moderate confidence that the operator may be Italian; that is an assessment, not an attribution.

How do I protect my AI servers?

Don’t expose management APIs to the internet, apply security updates, rebuild (not just clean) compromised systems, enforce egress controls, and rotate API keys and secrets.

Sources: The Hacker News, BleepingComputer, RuntimeWire.

Leave a Comment

Your email address will not be published. Required fields are marked *

Get the 5 best AI tools every week

Top AI news, tools, and prompts — one short email. Free, unsubscribe anytime.

Run a newsletter of your own? Monetize and grow it with SparkLoop →

Scroll to Top