PoeLLM mined more than 3,400 AI servers
LiteLLM, Ollama, Gotenberg and Gitea recruited since April

PoeLLM mined more than 3,400 AI servers

Lumen Technologies' Black Lotus Labs said on 7 October 2026 that a campaign it calls PoeLLM has compromised more than 3,400 servers since April. The operator hides command-and-control addresses inside a poem on GitHub. Four words from the poem are mapped through a hard-coded dictionary to a server address. Those words have been changed at least a dozen times.

What happened

The malware scans for exposed open-source services, exploits them, drops XMRig and Iron miners, and then uses the victim as another scanner. Peak activity was more than 800 active servers in a day. Most victims are in the United States and Western Europe. Researchers first saw the infrastructure in June while looking at Ivanti Sentry CVE-2026-10520.

Compromised hosts talk to Kryptex mining infrastructure. The payload also has remote-shell and exploit-deployment functions, so a mined box is not only a power bill. Lumen says what the operator does beyond scanning and mining is still under investigation. One write-up noted an authenticated command-execution bug in LiteLLM fixed in 1.83.7. That is not the whole campaign, and it is not an unauthenticated flaw.

Who is affected

  • Internet-exposed LiteLLM, Ollama, Gotenberg, and Gitea hosts.
  • Possible additional targeting of Ivanti Sentry.
  • Any lab or production GPU server that was published for convenience and never put behind a VPN.

What to do now

Remove LiteLLM, Ollama, Gotenberg, and Gitea from the public internet. If one of those was exposed, isolate the host, look for unexpected miners, and rebuild rather than cleaning in place. Patch LiteLLM to at least 1.83.7, but do not treat that version bump as proof the host was never recruited. Check outbound connections to unfamiliar mining pools and to GitHub fetches that do not match your own repos.

Source: CyberScoop, 7 October 2026. PoeLLM malware has assembled a sweeping botnet.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

ccTLD hijack minted fake certificates for Google
.gh, .sl and .as registries abused for trusted TLS certs