# Cryptomining malware hits over 3,400 servers using a GitHub poem

> The PoeLLM botnet, tracked since April 2026, uses four words in a poem on GitHub to steer infected AI servers to new mining controllers.

Oossa · 2026-10-11 · https://oossa.com/en/cryptomining-malware-hits-over-3-400-servers-using-a-github-poem

Researchers at Lumen’s Black Lotus Labs say the PoeLLM cryptomining botnet has infected more than 3,400 servers. The campaign, called Canto Incognito, has been active since at least April 2026. The malware hides its command‑and‑control address inside a two‑stanza poem on GitHub, using four specific words that change whenever the attackers move to a new server. So far the poem has been altered 11 times.

## How the infection spreads

Most of the compromised machines were running open‑source AI or large language model services such as LiteLLM and Ollama. An April 2026 fix for LiteLLM likely patched the route the malware used, but many servers remain exposed. Once a server is infected, PoeLLM drops XMRig and Iron mining tools that connect to the Kryptex mining pool. The infected host also becomes a scanner, looking for other vulnerable AI endpoints to hijack.

## What this means for server owners

The attackers appear financially motivated, linking the first 900 victims to a Russian crypto‑mining service. AI infrastructure is attractive because it often runs on powerful GPUs that can be repurposed for mining. Lumen says they have blocked traffic to and from the PoeLLM control servers, but the threat remains for any AI service that is not properly secured.

## The facts

- Over 3,400 servers have been infected by the PoeLLM malware.
- The campaign is named Canto Incognito and has been tracked since April 2026.
- The botnet’s control address is hidden in four words of a two‑stanza poem on GitHub, which has been changed 11 times.
- Infected servers run vulnerable versions of open‑source AI services like LiteLLM and Ollama.
- The payload drops XMRig and Iron miners that connect to Kryptex’s mining infrastructure.

## Why it matters

If you host AI models or LLM services, an unpatched version could be turned into a crypto‑miner without your knowledge, draining electricity and hardware performance. Keeping AI software up to date and restricting internet access to model endpoints can reduce this risk. It remains unclear how many active miners are still operating after Lumen’s traffic block.

## Sources & references

1. [Cryptomining malware that locates its control server in a GitHub poem has hit more than 3,400 servers, researchers say](https://www.tomshardware.com/tech-industry/cyber-security/cryptomining-malware-used-poetry-to-infect-more-than-3-400-servers-researchers-say-four-words-in-the-poellm-verse-changed-11-times-point-the-botnet-to-new-servers) – Tom's Hardware, 2026-10-11

Last updated: 2026-10-11
