"The Malware That Hides Its Command Server Inside a Poem"
Security researchers have a gift for naming things, and "PoeLLM" is a fine example. The name is a pun on Edgar Allan Poe and large language models, and it belongs to a piece of malware that, since April 2026, has compromised more than 3,000 exposed AI servers. The campaign, tracked by Lumen's Black Lotus Labs as "Canto Incognito," earns its literary name the honest way: it hides the address of its command-and-control server inside a poem posted on GitHub.
The technique is old even if the target is new. Malware authors have long used "dead drop resolvers" — pointing their bots at innocuous public infrastructure to learn where to phone home — whether that means DNS TXT records, Twitter bios, or Pastebin dumps. A poem on GitHub is just the latest twist. GitHub is trusted, almost never blocked by corporate firewalls, and its content can be edited server-side. That last part is the clever bit: an operator can rotate the command server's address simply by updating a text file, without ever touching the thousands of infected machines.
What's genuinely new is what PoeLLM hunts. Rather than chasing generic Linux boxes or unpatched web servers, it scans for open-source AI and LLM tooling — LiteLLM, Ollama, Gotenberg, Gitea, and possibly a vulnerable Ivanti Sentry deployment tracked as CVE-2026-10520. These are the gateways and runtimes that teams spin up when they want to self-host a model without paying per-token cloud prices. In the rush to stand up their own inference stack, many operators leave them internet-facing and misconfigured.
That last point is the real story underneath the headline. Ollama, for instance, ships without authentication by default because it's designed for local experimentation — but the same binary gets dropped on a cloud GPU instance, bound to 0.0.0.0, and left exposed. Add the fact that AI servers are, by definition, GPU-rich machines with abundant compute, and you have the perfect cryptomining target. PoeLLM's operators are not stealing model weights or prompt data; they're converting other people's expensive accelerators into free hash rate.
The campaign also behaves more like a worm than a one-off infection. Black Lotus Labs reports that compromised hosts get repurposed as scanners and exploit launchpads, actively hunting down new victims — which explains how the operation scaled to more than 800 new infections per day at its peak. An infection that can recruit its own hosts doesn't need a large crew or a clever lures; it just needs a single working exploit and a target population that's growing faster than it can be secured.
There's a useful distinction worth drawing here, because it's easy to misread this story as "AI is being hacked." PoeLLM doesn't attack the models or abuse their intelligence. It attacks the plumbing around them — the proxies, the runtimes, the API gateways — using techniques that would work against any misconfigured service. What changed is that this plumbing is suddenly everywhere, and a lot of it was deployed by data scientists and product teams who never considered themselves sysadmins.
That's why the response to PoeLLM matters less than the trend it confirms. For a couple of years, "AI security" was mostly a theoretical discipline — people argued about prompt injection and the OWASP Top 10 for LLM applications while MITRE ATLAS catalogued adversarial tactics. PoeLLM is the theory colliding with the real world: attackers now treat a self-hosted LLM gateway as just another internet-facing service to scan, exploit, and mine.
The practical takeaways are unglamorous but concrete. If you run Ollama or LiteLLM, put it behind authentication and a VPN or reverse proxy; don't expose management interfaces to the public internet; and treat a GPU box with the same segmentation discipline you'd give a database server. None of this requires a security vendor or a fancy AI firewall — it's the same hygiene we've been told to practice for twenty years, just pointed at a new class of machine.
For everyone else, PoeLLM is a reminder that the fastest-growing infrastructure tends to be the least defended. Every time a new tool lowers the barrier to self-hosting AI, it also lowers the barrier to owning that AI infrastructure. The poem on GitHub is a nice flourish, but the underlying lesson is older than either Poe or LLMs: convenience without configuration is an open door, and someone is always scanning for it.
Further reading: Lumen's Black Lotus Labs published the full technical breakdown of Canto Incognito, and BleepingComputer has a clear plain-English summary of the cryptomining angle.
Comments
Everyone fears the snake and misses the venom in the verses. Judging by looks again — Poe hid a whole command server in a poem and we only saw the rhyme scheme.
@crankyCobble98 Nevermore turned out to be load-bearing — we spent the whole poem admiring the meter while the meter was exfiltrating.
Leave a Comment