
Malware That Reads Its Orders From a Poem on GitHub Has Hit More Than 3,400 Exposed AI and Developer Servers
Lumen's Black Lotus Labs said on October 7 that PoeLLM, a cryptomining botnet it ties to an Italian-speaking actor, breaks into exposed LiteLLM, Ollama, Gotenberg and Gitea servers and finds its command server by decoding four words in a poem the operator edits on GitHub.
Ava Okello, DetectionLondon5 min read
LONDON - A cryptomining botnet that has broken into more than 3,400 internet-facing servers since April looks up its command server in an unusual place: four words in a two-stanza poem posted on GitHub, researchers at Lumen Technologies' Black Lotus Labs said on Wednesday. Black Lotus Labs calls the malware PoeLLM and the campaign Canto Incognito. It said most victims were running vulnerable versions of open-source AI and LLM services such as LiteLLM and Ollama, along with hundreds of servers running the Gotenberg PDF converter and the Gitea development toolkit. The researchers assessed that an Italian-speaking actor runs the operation, which appears to be financially motivated. For detection teams, the report shows two problems at once: a command lookup hidden in ordinary prose, and a class of self-hosted AI tools that, in Black Lotus Labs' words, "often go unmonitored for vulnerabilities despite access to powerful compute and valuable enterprise data."

The poem sits in a file named dash.css in a GitHub repository belonging to the user "ejejejdfbbebe." The repository is a fork of the nodejs.org website source, but the researchers said the malware does not appear to have any connection to Node.js, and the file name does not exist in the original repository. The poem, titled "On the Nature of Connection," has been updated 11 times since its first commit on April 13. A function in the malware named extract_poem_phrase_field pulls three words from fixed phrases ("In the silent hum of," "each pulse of" and "Beyond the wall of") and takes a fourth from the word after "the" that precedes "of distant servers." A hard-coded dictionary maps each word to a number, and the four numbers form an IPv4 address. In a sample found on June 23, "driver," "diode," "decryption" and "string" resolved to 92.119.165[.]74. When the operator stands up a new server, only the key words change, and infected machines work out the new address on their own. The parsing pattern has not changed across the 11 versions the researchers observed.

Black Lotus Labs came across the infrastructure while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. In early June, a compromised Ivanti Sentry device contacted a dedicated server at 5.78.73[.]122 and soon began scanning for other vulnerable devices. Lumen's netflow telemetry showed more than 1,000 other IP addresses talking to that server, and device data showed most of them running LiteLLM, Ollama, Gitea or Gotenberg. The first 900 victims had one more thing in common: contact with 5.180.174[.]162, an endpoint of the Russian mining service Kryptex. That led the researchers to an ELF file named libgcrypt that bundles a remote shell, the Iron and XMRig miners, HTTP and HTTPS scanning, and exploits for vulnerable targets. At the campaign's peak in mid-June, almost 2,200 servers were affected, with nearly 800 active per day.
The infection chain is plain once the ports are known. The operator scanned the internet mainly on ports 3000 and 4000, the listening ports for Gotenberg and LiteLLM. When a scan found a vulnerable host, an exploit server sent it a crafted POST request telling it to download a file from the command server on port 81. In one sample the researchers reviewed, the LiteLLM endpoint /mcp-rest/test/connection, which is referenced in the LiteLLM command injection flaw CVE-2026-42271, was likely the exploitation path. Once installed, the malware beaconed back on port 3778, 5001, 5002 or 9999. Infected machines were then put to work as scanners and exploit servers, producing large outbound flows to ports 3000 and 4000 on other targets. More recent traffic toward SSH and other login portals suggests the operator is experimenting with distributed brute-force attacks, though Black Lotus Labs said that capability's maturity remains uncertain. Notably, Gotenberg's own installation guide warns users not to expose the service to the internet.

Rather than rent servers, the operator kept turning compromised routers into command and file hosts. The first address decoded from the poem, 191.37.28[.]160, was a router in Brazil with an exposed Boa web server whose admin page was vulnerable to CVE-2018-21027 and CVE-2018-21028, though the researchers found no direct evidence of exploitation. About an hour after the first GitHub commit, that router contacted a server in Italy, 57.131.5[.]211, hosting the domain malwarescan[.]xyz, registered in February. A later command server in China, 120.224.114[.]212, showed the same vulnerable router pattern and kept in constant contact with 185.119.19[.]171, an Italian server that had hosted Prometheus and Uptime Kuma monitoring dashboards. Citing Italian-language comments in the malware, netflow and those services, Black Lotus Labs assessed with moderate confidence that this server is the actor's administrative interface. It counted 12 command server addresses in all, three of them still active at publication: 92.119.164[.]50, 103.249.201[.]108 and 178.128.14[.]204.
The indicators give SOC teams concrete places to look. On the network, that means outbound connections to the 12 listed command servers and to the Kryptex endpoints 5.180.174[.]162:8029 and 46.21.245[.]211:7029, downloads over port 81 from paths such as /private/python3.6 and /private/bins.sh, and beacons on the four callback ports. On the hosts, it means POST requests to /mcp-rest/test/connection on LiteLLM, AI or developer servers that suddenly start scanning ports 3000 and 4000 or making many SSH login attempts, and server workloads fetching a dash.css file from GitHub. Black Lotus Labs published the command servers and three malware hashes in its public IOC repository. It recommended inspecting network logs for those indicators, auditing external exposure after installing any new open-source tool, restricting service ports from outside access as far as possible, and keeping routers, firewalls and IoT devices patched and regularly rebooted.
Lumen said it has blocked all traffic to and from the PoeLLM command servers and that customers of its Lumen Defender service have been protected since the malware was discovered, and its post also promotes the company's managed SASE service. The broader warning stands apart from the sales pitch. Attackers "have realized that servers running AI/LLM implementations are attractive targets for compromise," the researchers wrote, "both for their value as sources of intelligence and for their appeal as self-hosted, internet-exposed services with known vulnerabilities." Here, they added, the GPU hardware behind those workloads may have been an extra draw for a profit-driven mining crew. "As AI becomes more involved in both development and day-to-day operations, and enterprises rapidly expand their attack surface by including AI infrastructure, the security of these agents cannot take a backseat to convenience," Black Lotus Labs wrote.
Sources:
- Lumen: Canto incognito: tracking the PoeLLM malware (Black Lotus Labs, Lumen Technologies, Oct 7, 2026)
- GitHub: PoeLLM IOCs (Black Lotus Labs)
- NVD: CVE-2026-42271 (NVD)
- NVD: CVE-2026-10520 (NVD)
- The Register: Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers (The Register, Oct 7, 2026)
Ava Okello covers detection engineering, EDR telemetry, and SOC hunting for SOCtember from London.
Related stories
Detection
Huntress Finds Threat Actor Compiling Silent XMR Miner Directly on Endpoint
Threat Intel
ClingSTUN Backdoor Turns Unpatched IoT Devices Into Proxies Hidden in Public STUN Traffic
Threat Intel
Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves
Threat Intel