Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet.

The campaign targets internet-facing services, including LiteLLM and Ollama, while also affecting Gotenberg PDF converters and Gitea development servers.

Active since at least April 2026, PoeLLM uses selected words in the poem to calculate its next control server address. Changing those words lets the attacker redirect infected machines without replacing the malware.

Compromised servers also become scanners and exploit workers, helping the operation reach more victims. Researchers from Lumen’s Black Lotus Labs identified the malware while investigating activity linked to an Ivanti Sentry vulnerability in June.

Their technical report, published October 7, describes more than 3,400 affected servers in its overview, although sections retain an earlier figure of almost 2,200. Most victims were in the United States and Western Europe.

Hackers Use GitHub-Hosted Poem

The attacker placed a poem titled “On the Nature of Connection” inside a file in a GitHub repository forked from the Node.js website source code. Researchers found no apparent connection between the malware and the legitimate Node.js project.

PoeLLM extracts four words or phrases using fixed text markers. A dictionary stored inside the malware maps each extracted value to a number. Together, those four numbers form the IPv4 address of the current command-and-control server.

Campaign overview (Source – Canto)

One example maps “driver,” “diode,” “decryption,” and “string” to four address components. Researchers observed 11 poem updates after the initial April 13 commit, while the decoding pattern stayed unchanged.

This makes rotation simple: the operator changes selected words, and infected systems calculate the replacement address.

Exposed AI Services Fuel Botnet Growth

Broader scanning began in May, with traffic focused on ports associated with Gotenberg and LiteLLM. Crafted POST requests instructed vulnerable systems to download payloads from the attacker’s infrastructure.

Researchers linked one likely LiteLLM attack path to command injection vulnerability CVE-2026-42271, previously covered in LiteLLM exploitation reporting.

The Linux ELF payload combines remote-shell access, HTTP/S scanning, exploit delivery, and XMRig and Iron cryptocurrency miners.

Infected machines contacted Kryptex mining services and supplied additional workers for the botnet. The same exposure problem appears in earlier coverage of publicly accessible Ollama servers.

Researchers also observed traffic toward SSH and other login portals, suggesting experiments with distributed password guessing. They could not establish how mature that capability was.

Italian-language code comments and network evidence suggest an Italian-speaking operator, not a confirmed identity. Several control servers exposed vulnerable router administration pages.

Researchers suspect the attacker reused compromised routers, but found no direct exploitation evidence for the first router’s two identified vulnerabilities.

Lumen recommends reviewing network logs, limiting public access, and including AI tools in regular patching and exposure checks. Gotenberg’s installation guidance warns against direct internet exposure. Routers, firewalls, and other edge devices also require timely updates.

PoeLLM demonstrates direct server exploitation rather than a proven package compromise or stolen-model-access scheme.

Related coverage of the LiteLLM supply-chain compromise and LLMjacking through leaked AWS credentials shows other routes into AI environments; those incidents should not be confused with this campaign.

Indicators of compromise (IoCs):-

Type Indicator Context
SHA-256 6fab94577364beec314afae3b082dd680933f08a8349b9f35b92667e8231b501 Reviewed sample
C2 92.119.164[.]50 Active
C2 103.249.201[.]108 Active
C2 178.128.14[.]204 Active
C2 191.37.28[.]160 Historical
C2 89.39.253[.]46 Historical
C2 120.224.114[.]212 Historical
C2 5.78.73[.]122 Historical
C2 15.204.178[.]28 Historical
C2 92.119.165[.]74 Historical
C2 45.133.73[.]28 Historical
C2 185.132.53[.]158 Historical
C2 136.148.69[.]233 Historical
Suspected administration 185.119.19[.]171 Moderate-confidence assessment
Associated server 57.131.5[.]211:80 Initial infrastructure contact
Associated domain malwarescan[.]xyz Possible operator service
Mining endpoint 5.180.174[.]162:8029 Kryptex
Mining endpoint 46.21.245[.]211:7029 Kryptex
Mining domain edge-ru-07[.]kryptex[.]network Pool host
Mining domain Kryptex[.]ru Pool service
Payload URL hxxp://5.78.73[.]122:81/private/python3.6 Download
Payload URL hxxp://5.78.73[.]122:81/private/bins.sh Download
File libgcrypt Malware filename
GitHub account ejejejdfbbebe Poem publisher
Repository file dash.css Poem storage
Target endpoint /mcp-rest/test/connection Likely exploitation path
C2 ports 3778, 5001, 5002, 9999 Beacon traffic
Other ports 81; 3000, 4000; 2222 Downloads; scanning; router interface

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.