It Takes Orders From a Poem: PoeLLM Turned 3,400 Exposed AI Servers Into Miners

A cryptocurrency-mining campaign dubbed PoeLLM has compromised more than 3,400 servers by walking through the front doors of exposed AI infrastructure. Active since April 2026, the operation — detailed by Black Lotus Labs in a report shared with GBHackers on 8 October — combines vulnerability exploitation, XMRig and Iron miners, and a command-and-control scheme that derives server addresses from a poem hosted on GitHub. Victims predominantly run LiteLLM, Ollama, Gotenberg and Gitea, with possible targeting of Ivanti Sentry, concentrated in the United States and Western Europe. Peak activity exceeded 800 active servers a day, and compromised machines were conscripted as scanners — victim infrastructure distributing the campaign's expansion.

If you run AI serving infrastructure with its console on the internet, this is your campaign. If you assume internal-tool authentication is a formality, it is also your CVE.

Command and control by poetry

PoeLLM retrieves its control instructions from “On the Nature of Connection,” a poem embedded in a file named dash.css inside a fork of the Node.js website repository — researchers found no connection to legitimate Node.js software. The malware extracts four words or phrases using fixed textual markers, then maps them through a hardcoded dictionary to numerical values that become the four octets of an IPv4 address. To redirect the botnet, the operator edits the poem. Researchers observed 11 poem updates since the repository's initial 13 April commit, and because the decoding pattern never changed, investigators could reconstruct every infrastructure transition — including the first decoded C2, which appears to have tested the infection process. The trail surfaced during investigation of a compromised Ivanti Sentry box contacting 5.78.73[.]122 and then scanning its neighbours; telemetry showed broad scanning against ports 3000 and 4000, the Gotenberg and LiteLLM neighbourhoods.

The LiteLLM door was authenticated — and open anyway

One analysed sample referenced LiteLLM's /mcp-rest/test/connection endpoint, consistent with CVE-2026-42271: versions 1.74.2 through versions preceding 1.83.7 permit authenticated users — including low-privilege API-key holders — to execute commands through supplied MCP configurations. Version 1.83.7 fixes it. Be precise about what this means: it is authenticated command execution, not an unauthenticated flaw. The campaign's scale is therefore a census of exposed consoles guarded by weak, leaked or default credentials — the exact posture we keep finding on AI runtimes. Successful attacks pointed targets at payload servers on port 81; infected systems then talked C2 over ports 3778, 5001, 5002 or 9999. Several decoded command servers themselves exposed vulnerable Boa router admin interfaces — the operator reuses compromised network devices as infrastructure, botnet all the way down.

The landed payload, an ELF named libgcrypt, bundles remote-shell capability, HTTP/S scanning, exploit deployment and the miners; victims were seen contacting Kryptex mining infrastructure. Recent traffic toward SSH services and login portals suggests experiments with distributed brute force, assessed as immature — a capability to watch rather than a current fire. As this week's Pwn2Own AI track underlined, AI infrastructure is now a contest target and a crime target simultaneously; the difference is that contests end.

What to do

  • Upgrade LiteLLM to 1.83.7 or later and rotate every API key on any instance that was ever internet-reachable. Low-privilege keys were sufficient for command execution — “read-only key” was never true.
  • Take AI consoles and MCP test endpoints off the internet. Ollama, Gotenberg, Gitea and LiteLLM admin surfaces have no business on routable addresses; the campaign's port-3000/4000 scanning exists because defenders keep putting them there.
  • Hunt the poem-C2 indicators: unexpected fetches of dash.css-style content from repository forks, miners (libgcrypt, XMRig/Iron pool traffic to Kryptex infrastructure), and outbound connections on 3778/5001/5002/9999.
  • Read the counts as snapshots, not contradictions: the 3,400+ headline is cumulative compromises, ~800 is peak daily-active, ~2,200 an earlier-section figure. Any of them is too many internet-facing model servers.

Verification note: the PoeLLM name, the 3,400+ cumulative figure alongside the ~800 daily-active and ~2,200 earlier-section figures, the April 2026 start, the LiteLLM/Ollama/Gotenberg/Gitea victim profile with possible Ivanti Sentry targeting, the US/Western Europe concentration, the “On the Nature of Connection”/dash.css/Node.js-fork mechanism with four marker-extracted words mapped to IPv4 octets, the 11 poem updates since the 13 April commit, the CVE-2026-42271 version range and 1.83.7 fix, the authenticated-including-low-privilege-keys characterisation, the /mcp-rest/test/connection reference, the libgcrypt payload contents, the Kryptex contacts, the port set, the Boa-router reuse and the immature SSH brute-forcing were read directly from GBHackers' 8 October write-up of the Black Lotus Labs report. The CVE-2026-42271 range and fix version are corroborated by secondary trade coverage. We have not seen the underlying Black Lotus Labs report, independently decoded the poem, or tested the LiteLLM exploit; severity characterisation of exposed instances is our assessment.

Sources: