Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet.
The campaign targets internet-facing services, including LiteLLM and Ollama, while also affecting Gotenberg PDF converters and Gitea development servers.
Active since at least April 2026, PoeLLM uses selected words in the poem to calculate its next control server address. Changing those words lets the attacker redirect infected machines without replacing the malware.
Compromised servers also become scanners and exploit workers, helping the operation reach more victims. Researchers from Lumen’s Black Lotus Labs identified the malware while investigating activity linked to an Ivanti Sentry vulnerability in June.
Their technical report, published October 7, describes more than 3,400 affected servers in its overview, although sections retain an earlier figure of almost 2,200. Most victims were in the United States and Western Europe.
Hackers Use GitHub-Hosted Poem
The attacker placed a poem titled “On the Nature of Connection” inside a file in a GitHub repository forked from the Node.js website source code. Researchers found no apparent connection between the malware and the legitimate Node.js project.
PoeLLM extracts four words or phrases using fixed text markers. A dictionary stored inside the malware maps each extracted value to a number. Together, those four numbers form the IPv4 address of the current command-and-control server.
One example maps “driver,” “diode,” “decryption,” and “string” to four address components. Researchers observed 11 poem updates after the initial April 13 commit, while the decoding pattern stayed unchanged.
This makes rotation simple: the operator changes selected words, and infected systems calculate the replacement address.
Exposed AI Services Fuel Botnet Growth
Broader scanning began in May, with traffic focused on ports associated with Gotenberg and LiteLLM. Crafted POST requests instructed vulnerable systems to download payloads from the attacker’s infrastructure.
Researchers linked one likely LiteLLM attack path to command injection vulnerability CVE-2026-42271, previously covered in LiteLLM exploitation reporting.
The Linux ELF payload combines remote-shell access, HTTP/S scanning, exploit delivery, and XMRig and Iron cryptocurrency miners.
Infected machines contacted Kryptex mining services and supplied additional workers for the botnet. The same exposure problem appears in earlier coverage of publicly accessible Ollama servers.
Researchers also observed traffic toward SSH and other login portals, suggesting experiments with distributed password guessing. They could not establish how mature that capability was.
Italian-language code comments and network evidence suggest an Italian-speaking operator, not a confirmed identity. Several control servers exposed vulnerable router administration pages.
Researchers suspect the attacker reused compromised routers, but found no direct exploitation evidence for the first router’s two identified vulnerabilities.
Lumen recommends reviewing network logs, limiting public access, and including AI tools in regular patching and exposure checks. Gotenberg’s installation guidance warns against direct internet exposure. Routers, firewalls, and other edge devices also require timely updates.
PoeLLM demonstrates direct server exploitation rather than a proven package compromise or stolen-model-access scheme.
Related coverage of the LiteLLM supply-chain compromise and LLMjacking through leaked AWS credentials shows other routes into AI environments; those incidents should not be confused with this campaign.
Indicators of compromise (IoCs):-
| Type | Indicator | Context |
|---|---|---|
| SHA-256 | 6fab94577364beec314afae3b082dd680933f08a8349b9f35b92667e8231b501 |
Reviewed sample |
| C2 | 92.119.164[.]50 |
Active |
| C2 | 103.249.201[.]108 |
Active |
| C2 | 178.128.14[.]204 |
Active |
| C2 | 191.37.28[.]160 |
Historical |
| C2 | 89.39.253[.]46 |
Historical |
| C2 | 120.224.114[.]212 |
Historical |
| C2 | 5.78.73[.]122 |
Historical |
| C2 | 15.204.178[.]28 |
Historical |
| C2 | 92.119.165[.]74 |
Historical |
| C2 | 45.133.73[.]28 |
Historical |
| C2 | 185.132.53[.]158 |
Historical |
| C2 | 136.148.69[.]233 |
Historical |
| Suspected administration | 185.119.19[.]171 |
Moderate-confidence assessment |
| Associated server | 57.131.5[.]211:80 |
Initial infrastructure contact |
| Associated domain | malwarescan[.]xyz |
Possible operator service |
| Mining endpoint | 5.180.174[.]162:8029 |
Kryptex |
| Mining endpoint | 46.21.245[.]211:7029 |
Kryptex |
| Mining domain | edge-ru-07[.]kryptex[.]network |
Pool host |
| Mining domain | Kryptex[.]ru |
Pool service |
| Payload URL | hxxp://5.78.73[.]122:81/private/python3.6 |
Download |
| Payload URL | hxxp://5.78.73[.]122:81/private/bins.sh |
Download |
| File | libgcrypt |
Malware filename |
| GitHub account | ejejejdfbbebe |
Poem publisher |
| Repository file | dash.css |
Poem storage |
| Target endpoint | /mcp-rest/test/connection |
Likely exploitation path |
| C2 ports | 3778, 5001, 5002, 9999 |
Beacon traffic |
| Other ports | 81; 3000, 4000; 2222 |
Downloads; scanning; router interface |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.