Lumen Researchers Report PoeLLM Cryptominer Infects Over 3,400 AI Servers
Threat researchers identify a cryptominer targeting exposed LiteLLM and Ollama instances, using GitHub poetry for command-and-control communication.
Key points
- Lumen's Black Lotus Labs reports the PoeLLM malware has compromised more than 3,400 servers globally.
- The majority of affected systems run exposed AI inference tools, specifically LiteLLM and Ollama.
- The malware utilizes GitHub repositories containing poems to store and retrieve command-and-control instructions.
Lumen’s Black Lotus Labs has identified a widespread cryptomining campaign targeting exposed AI infrastructure. The group reports that the PoeLLM malware has successfully infected more than 3,400 servers, leveraging a novel command-and-control method.
What happened
Lumen’s Black Lotus Labs published findings indicating that the PoeLLM cryptominer has compromised more than 3,400 servers. According to Tom's Hardware, the researchers observed that most of these victims were running exposed AI tools. The malware specifically targets instances of LiteLLM and Ollama that lack proper authentication or network restrictions.
The threat actors employ a unique technique for command-and-control communication. Instead of using traditional domains or IP addresses, the malware retrieves instructions from GitHub repositories. These repositories contain poems, which encode the commands the malware needs to execute on the infected servers.
This method allows the attackers to blend their traffic with legitimate GitHub activity. The use of poetry as a carrier for C2 data makes detection more difficult for standard security tools. Researchers noted that the malware scans for vulnerable AI endpoints before deploying the mining payload.
Why it matters
The scale of the infection highlights the risks of deploying AI tools without adequate security controls. With over 3,400 servers affected, the campaign demonstrates how quickly attackers can exploit misconfigured software. Organizations running LiteLLM or Ollama are particularly vulnerable if these tools are accessible from the public internet.
The use of GitHub for C2 communication represents a shift in attacker behavior. Security teams may not monitor GitHub traffic for malicious intent, allowing the malware to operate undetected for longer periods. This technique bypasses many traditional perimeter defenses that focus on known malicious domains.
Exposed AI tools often process sensitive data, making them high-value targets. Compromising these servers allows attackers to consume significant computational resources. The financial impact includes increased electricity costs and potential degradation of service for legitimate users.
What to watch
- Monitor network logs for unusual outbound connections to GitHub repositories, especially those accessing raw text files.
- Audit all deployments of LiteLLM and Ollama to ensure they are not exposed to the public internet.
- Look for signs of unauthorized cryptocurrency mining processes consuming high CPU or GPU resources.
- Review access controls on AI inference endpoints to enforce strict authentication and IP whitelisting.
- Check for new or modified GitHub repositories associated with your organization that may be used for C2.
Background: IP addresses
An IP address is a numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication. This guide answers ten common questions about IPv4 and IPv6 mechanics, subnetting, NAT, and security implications to clarify how these identifiers function in modern infrastructure.
Read the full guide: IP Address Mechanics: 10 Questions Network Engineers Actually Ask
What to do and how to stay safe: PoeLLM
- Restrict network access to AI inference tools like LiteLLM and Ollama to trusted internal IPs only.
- Implement strong authentication mechanisms for all administrative and API endpoints of AI services.
- Monitor server resource usage for sudden spikes in CPU or GPU activity indicative of cryptomining.
- Once the vendor provides an update, apply patches immediately to address any known vulnerabilities in AI frameworks.
- Review firewall rules to block unnecessary outbound traffic to code hosting platforms like GitHub.
Step-by-step guide: Ransomware Incident Response: The Technical Reality of Containment and Recovery
General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is PoeLLM malware?
PoeLLM is a cryptomining malware that targets exposed AI tools and uses GitHub poems for command-and-control communication.
Which AI tools are affected by this campaign?
The campaign primarily targets exposed instances of LiteLLM and Ollama, according to Lumen's Black Lotus Labs.
How many servers have been compromised?
Researchers report that more than 3,400 servers have been infected by the PoeLLM cryptominer.




