Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit GitHub Poem for AI Malware Control

Hackers Exploit GitHub Poem for AI Malware Control

Posted on October 8, 2026 By CWS

Cybercriminals have innovatively harnessed a poem hosted on GitHub to guide the PoeLLM malware, effectively commandeering exposed AI infrastructure into an expanding botnet for cryptocurrency mining.

This malicious campaign impacts numerous internet-based services such as LiteLLM and Ollama, as well as Gotenberg PDF processors and Gitea development servers.

Unveiling the PoeLLM Malware Strategy

Since April 2026, the PoeLLM malware has utilized specific words within the poem to compute the address of its command-and-control servers. Modifying these words allows attackers to redirect infected systems without modifying the malware itself.

Compromised servers are leveraged as scanners and exploit tools, broadening the scope of the attack. Researchers from Lumen’s Black Lotus Labs detected this malware while probing activities related to a vulnerability in Ivanti Sentry in June.

Their findings, published on October 7, indicate that over 3,400 servers have been compromised, with the majority located in the United States and Western Europe.

GitHub Poem: An Unorthodox Control Mechanism

The attackers stored a poem titled “On the Nature of Connection” in a GitHub repository, which was a fork from the Node.js source code. There appears to be no direct link between the malware and the legitimate Node.js project.

PoeLLM extracts four key phrases from the poem using fixed text markers, which are then mapped to numbers stored within the malware. These numbers collectively form the IP address of the malware’s control server.

Though the poem underwent 11 updates since its initial release on April 13, the underlying decryption pattern remained unchanged, simplifying the process for the attackers to rotate server addresses by merely altering selected words.

Scaling the Botnet with Exposed AI Services

In May, broader scanning activities commenced, concentrating on ports linked to Gotenberg and LiteLLM. Vulnerable systems were directed to download malicious payloads via crafted POST requests.

Researchers traced a potential LiteLLM attack vector to a command injection vulnerability, CVE-2026-42271, previously documented in LiteLLM exploitation reports.

The Linux ELF payload combines functionalities for remote access, HTTP/S scanning, exploit deployment, alongside XMRig and Iron cryptocurrency miners, leading compromised systems to communicate with Kryptex mining services.

Implications and Recommendations

The investigation hints at possible Italian origins for the hackers due to Italian-language code comments, although a definitive identity remains unconfirmed. Compromised routers with exposed administrative interfaces were also noted.

Lumen advises organizations to scrutinize network logs, restrict public access, and incorporate AI tools into regular updates and exposure assessments.

PoeLLM illustrates a direct server exploitation case rather than a supply-chain attack or unauthorized model access, differing from past incidents involving LiteLLM supply-chain breaches and AWS credential leaks.

Cyber Security News Tags:AI security, Black Lotus Labs, Botnet, cryptocurrency mining, Cybersecurity, GitHub, Gotenberg, Infrastructure, Ivanti Sentry, LiteLLM, Lumen, Malware, network security, PoeLLM, Vulnerabilities

Post navigation

Previous Post: Owner Charged in $11M Fraudulent Ransomware Scheme
Next Post: 16 Harmful Firefox Add-ons Imitate Wallets to Steal Data

Related Posts

ZendTo Vulnerability Let Attackers Bypass Security Controls and Access Sensitive Data ZendTo Vulnerability Let Attackers Bypass Security Controls and Access Sensitive Data Cyber Security News
Post-Quantum Cryptography What CISOs Need to Know Post-Quantum Cryptography What CISOs Need to Know Cyber Security News
Critical NGINX Security Flaws Patched by F5 Critical NGINX Security Flaws Patched by F5 Cyber Security News
New Ransomware ‘Payload’ Targets Windows and ESXi New Ransomware ‘Payload’ Targets Windows and ESXi Cyber Security News
AmnesiaStealer Malware Targets macOS Through Fake Sites AmnesiaStealer Malware Targets macOS Through Fake Sites Cyber Security News
FortiClient Exploitation Leads to EKZ Malware Deployment FortiClient Exploitation Leads to EKZ Malware Deployment Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TP-Link Faces Legal Actions Over Security Concerns
  • 16 Harmful Firefox Add-ons Imitate Wallets to Steal Data
  • Hackers Exploit GitHub Poem for AI Malware Control
  • Owner Charged in $11M Fraudulent Ransomware Scheme
  • Ransomware Fraud: MonsterCloud Owner Charged with $19M Scheme

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TP-Link Faces Legal Actions Over Security Concerns
  • 16 Harmful Firefox Add-ons Imitate Wallets to Steal Data
  • Hackers Exploit GitHub Poem for AI Malware Control
  • Owner Charged in $11M Fraudulent Ransomware Scheme
  • Ransomware Fraud: MonsterCloud Owner Charged with $19M Scheme

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark