Threats & Adversaries · Cryptojacking

PoeLLM Hides Its C2 in GitHub Poetry

Lumen’s Black Lotus Labs says PoeLLM has infected more than 3,400 exposed AI and LLM servers since April, turning them into a cryptomining botnet that also scans for more victims. The campaign has hit internet-facing systems including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry, and it continues to grow.

The malware does not carry a fixed command-and-control address. Instead, it reads a few words from a poem hosted on GitHub, combines them with a hard-coded dictionary, and reconstructs the real C2 server from that harmless-looking text. That makes the coordination point harder to spot and shift than a normal domain or IP blacklist, while infected hosts are also reused as scanners and exploit launchpads.

For teams running exposed AI services or other public-facing appliances, the exposure is not just wasted CPU from mining. A single foothold can become a node in someone else’s attack infrastructure, and cleanup that focuses only on mining leaves the scanning and downstream-compromise role intact until the infected host is removed.

4 sources · 5h ago

CVE-2026-42271

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 93% (100th percentile).

CISA federal remediation date Jun 22 · date passed

CVE-2026-10520

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…

CISA federal remediation date Jun 14 · date passed

CVE-2026-48710

NVD KEV

Known exploited · CISA KEV

CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.

CISA federal remediation date Sep 16 · date passed

Timeline

Sources

Vendor digest: Ivanti

Part of the PlainSec briefing for 2026-10-07

Every edition of this story: PoeLLM Hides Its C2 in GitHub Poetry

More from today