The short answer: PoeLLM is a new Linux malware campaign that has quietly taken over more than 3,400 internet-exposed AI servers since April 2026, turning them into cryptocurrency miners. Its most unusual trick is hiding its command-and-control server addresses inside a poem hosted on GitHub, so it can move its infrastructure without ever updating the malware itself. If you run LiteLLM or any exposed AI service, update to LiteLLM 1.83.7 or later, lock down public access, and check your systems for compromise.
What Is PoeLLM Malware?
PoeLLM is a Linux malware campaign discovered by Lumen’s Black Lotus Labs during a parallel investigation in June 2026, and disclosed publicly in October 2026. The malware arrives as an ELF binary disguised with the name libgcrypt, a name chosen to blend in with legitimate system libraries.
Instead of targeting ordinary desktops or web servers, PoeLLM goes after exposed AI infrastructure: LiteLLM proxy servers, Ollama instances, Gotenberg document converters, and Gitea instances that are reachable from the public internet. These machines are attractive targets because they often run on powerful GPU hardware, are frequently misconfigured, and are left exposed online with their management APIs wide open.
Once installed, PoeLLM does three things: it mines cryptocurrency using the stolen compute, it opens a remote shell for the operator, and it scans the internet for new victims so the botnet keeps growing. Black Lotus Labs estimates the campaign has compromised more than 3,400 servers since April 2026.
How PoeLLM Hides Its Command Servers in a Poem
The cleverest part of the campaign is how infected machines find their command-and-control (C2) server. Normally, malware either hard-codes an IP address or a domain name, which defenders can block. PoeLLM does something different: it reads a poem.
The poem, titled “On the Nature of Connection,” is stored in a file called dash.css inside a GitHub repository set up by a user going by “ejejejdfbbebe” (the repo is a fork of the nodejs.org website source, though it has no real connection to Node.js). The malware pulls four words from fixed positions in the poem and converts each word into a number using a dictionary hard-coded into the malware. Those four numbers become an IPv4 address.
For example, in one earlier version of the poem, the words “driver,” “diode,” “decryption” and “string” translated to 92, 119, 165 and 74, giving a C2 address of 92.119.165.74.
When the operator wants to move to a new server, they simply edit the poem. Infected machines read the updated text and silently switch to the new address. The poem has been edited 11 times since the first commit on April 13, 2026, and researchers suspect at least one more update has happened since. This means blocking known C2 IP addresses alone will not stop the campaign for long.
How the Attack Works
Finding targets
Compromised servers double as scouts. They scan the internet on ports 3000 and 4000, which are commonly associated with Gotenberg and LiteLLM deployments, looking for exposed management endpoints. Each newly infected host adds mining capacity and a new vantage point for finding the next victim.
Breaking in through LiteLLM
The main entry point identified in analyzed samples is LiteLLM’s MCP server test endpoint at /mcp-rest/test/connection, tied to CVE-2026-42271, a command injection vulnerability. The flaw affects LiteLLM versions 1.74.2 through 1.83.6. It was originally disclosed as requiring authentication (a valid proxy API key, though even low-privilege keys work), but researchers at Horizon.ai confirmed it can be chained with CVE-2026-48710, a Starlette host-header validation bypass, to achieve unauthenticated remote code execution.
How the attackers obtained API keys in cases where authentication was needed is still unconfirmed.
The payload
Once inside, PoeLLM drops the miners XMRig and Iron and starts generating cryptocurrency. Infected hosts were observed communicating with Kryptex, a Russian cryptomining service. The malware also carries a remote shell, an HTTP/HTTPS scanner, and exploit-delivery modules, so it can be used for more than mining. Black Lotus Labs also saw the malware probing SSH and login portals in what looks like an early-stage capability that is still being developed.
Resilient infrastructure
Analysis of the C2 infrastructure showed that several command servers had vulnerable router administration interfaces, suggesting the operator reused compromised routers to host parts of the operation. Combined with the poem-based addressing, this gives the campaign unusual resilience against takedowns.
Who Is Behind PoeLLM?
No one has been definitively identified. Black Lotus Labs assesses with moderate confidence that the operator is Italian-speaking, based on comments found in the malware code and an Italy-based server hosting the administrative interface. That is an assessment, not a confirmed identification, and the researchers were careful to say confident attribution was not possible.
What to Do Right Now
If you run AI or developer infrastructure, treat this as an active threat:
- Patch LiteLLM immediately. Upgrade to LiteLLM 1.83.7 or later, which fixes CVE-2026-42271. Also make sure Starlette is at 1.0.1 or later to close the chained CVE-2026-48710 path.
- Reduce internet exposure. AI tool management APIs should not be reachable from the public internet. Restrict external access to trusted IP addresses only, and review your external attack-surface inventory.
- Look for compromise. Check network logs for connections to the indicators of compromise shared by Black Lotus Labs, and watch for unexpected XMRig or Iron processes and outbound connections to unknown mining services.
- Rebuild, rotate, restrict. Any compromised system should be rebuilt from clean images rather than just cleaned. Rotate all API keys, tokens, and credentials that were present on affected hosts, and enforce egress controls so servers can only talk to approved destinations.
Why This Matters
PoeLLM marks a shift in how attackers think about AI infrastructure. These systems are no longer just another web application to exploit; they are treated as a source of data, GPU compute, credentials, and attack capacity in their own right. The campaign also shows how malware authors are borrowing resilience techniques from other playbooks. The poem-based C2 is a low-tech but effective answer to infrastructure takedowns, and it will be difficult for defenders who rely only on IP blocklists.
For teams running AI-adjacent services like the GitLab AI Gateway, the lesson is the same one from earlier campaigns such as the Tensorlake npm compromise: anything AI-related that faces the internet will be found, probed, and exploited. Patch fast, expose less, and monitor for the signs.
Frequently Asked Questions
What is PoeLLM malware?
PoeLLM is a Linux malware campaign that infects exposed AI and developer servers and turns them into cryptocurrency miners. It is named for its unusual command-and-control method: deriving server IP addresses from a poem hosted on GitHub. It was discovered by Lumen’s Black Lotus Labs and disclosed in October 2026.
How many servers has PoeLLM infected?
Black Lotus Labs reports more than 3,400 servers compromised since the campaign began in April 2026. An earlier-phase figure of around 2,200 servers describes a different measurement period, not the full campaign total.
Which software does PoeLLM target?
The confirmed targets include LiteLLM (via CVE-2026-42271 in its MCP server test endpoints), plus exposed Ollama, Gotenberg, and Gitea services. The malware scans ports 3000 and 4000 to find candidates.
How does the GitHub poem trick work?
The malware reads a poem from a GitHub repository, takes four words from fixed positions, and maps each word to a number with a built-in dictionary. The four numbers form the current C2 IP address. Editing the poem moves all infected machines to a new server without updating the malware.
How do I protect my servers from PoeLLM?
Update LiteLLM to version 1.83.7 or later (and Starlette to 1.0.1 or later), stop exposing AI management APIs to the public internet, restrict access to trusted IPs, check logs against published IoCs, rebuild any compromised hosts, and rotate all credentials.
Is PoeLLM related to the Shai-Hulud worm?
No, they are separate campaigns, though both target developer and AI tooling. Shai-Hulud spread through compromised npm packages, as covered in our Tensorlake analysis, while PoeLLM attacks exposed servers directly. The Warlock ransomware attacks show the same pattern: one unpatched, internet-facing service is all it takes.
