WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Chips & Hardware SINGLE SOURCE

Cryptomining malware that locates its control server in a GitHub poem has hit more than 3,400 servers, researchers say

Contemporary computer with black screen placed on stand near row of server steel racks in data center
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

Over 3,400 “victim servers” were hit by cryptomining malware (software written to damage a system or steal from it) PoeLLM during a campaign named Canto Incognito, tracked since April 2026, Lumen’s cybersecurity research team Black Lotus Labs reports . Most of those hit look to be running “vulnerable versions of open-source AI/LLM (the kind of AI system trained on text to produce text) services, such as LiteLLM and Ollama,” despite an April LiteLLM fix that probably patched the exploitation path.

Lumen's Black Lotus Labs says PoeLLM malware has hit more than 3,400 servers, most of them exposed AI tools like LiteLLM and Ollama. The malware’s “command-and-control (C2) mechanism” used address encoding through four words in a two-stanza poem on GitHub, altered 11 times so far, to direct affected hosts to new C2 servers.

The malware’s payload consists of XMRig and Iron miners, connected to Kryptex mining infrastructure, with infected servers becoming scanners and exploit servers. The “primary commonality amongst the first 900 victims” was contact with “an endpoint for the Russian crypto mining service,” Lumen says.

Sources & evidence