Cybercriminals have innovatively harnessed a poem hosted on GitHub to guide the PoeLLM malware, effectively commandeering exposed AI infrastructure into an expanding botnet for cryptocurrency mining.
This malicious campaign impacts numerous internet-based services such as LiteLLM and Ollama, as well as Gotenberg PDF processors and Gitea development servers.
Unveiling the PoeLLM Malware Strategy
Since April 2026, the PoeLLM malware has utilized specific words within the poem to compute the address of its command-and-control servers. Modifying these words allows attackers to redirect infected systems without modifying the malware itself.
Compromised servers are leveraged as scanners and exploit tools, broadening the scope of the attack. Researchers from Lumen’s Black Lotus Labs detected this malware while probing activities related to a vulnerability in Ivanti Sentry in June.
Their findings, published on October 7, indicate that over 3,400 servers have been compromised, with the majority located in the United States and Western Europe.
GitHub Poem: An Unorthodox Control Mechanism
The attackers stored a poem titled “On the Nature of Connection” in a GitHub repository, which was a fork from the Node.js source code. There appears to be no direct link between the malware and the legitimate Node.js project.
PoeLLM extracts four key phrases from the poem using fixed text markers, which are then mapped to numbers stored within the malware. These numbers collectively form the IP address of the malware’s control server.
Though the poem underwent 11 updates since its initial release on April 13, the underlying decryption pattern remained unchanged, simplifying the process for the attackers to rotate server addresses by merely altering selected words.
Scaling the Botnet with Exposed AI Services
In May, broader scanning activities commenced, concentrating on ports linked to Gotenberg and LiteLLM. Vulnerable systems were directed to download malicious payloads via crafted POST requests.
Researchers traced a potential LiteLLM attack vector to a command injection vulnerability, CVE-2026-42271, previously documented in LiteLLM exploitation reports.
The Linux ELF payload combines functionalities for remote access, HTTP/S scanning, exploit deployment, alongside XMRig and Iron cryptocurrency miners, leading compromised systems to communicate with Kryptex mining services.
Implications and Recommendations
The investigation hints at possible Italian origins for the hackers due to Italian-language code comments, although a definitive identity remains unconfirmed. Compromised routers with exposed administrative interfaces were also noted.
Lumen advises organizations to scrutinize network logs, restrict public access, and incorporate AI tools into regular updates and exposure assessments.
PoeLLM illustrates a direct server exploitation case rather than a supply-chain attack or unauthorized model access, differing from past incidents involving LiteLLM supply-chain breaches and AWS credential leaks.
