A four-word GitHub poem rerouted 3,400 servers to miners
Researchers say attackers used a four-word GitHub poem to steer compromised AI hosts to changing command centers, revealing a new way to monetize breached infrastructure.
PoeLLM cryptomining malware has infected over 3,400 servers in the Canto Incognito campaign since spring 2026.
The attack uses a four-word two-stanza poem on GitHub to direct infected machines to new command-and-control servers, changing up to 11 times.
Victims largely run open-source AI tools such as LiteLLM and Ollama, with miners tied to Kryptex infrastructure.
Quick read · 1 min
A cryptomining threat called PoeLLM has infected more than 3,400 servers since spring 2026 in the Canto Incognito campaign. The attackers hide the command-and-control address inside a four-word GitHub poem, switching to new C2 servers up to 11 times.
Many affected machines run open-source AI tools like LiteLLM and Ollama. The campaign appears financially motivated, with early connections to a Russian mining endpoint. Victims should review exposed AI services, patch vulnerabilities, and monitor outbound traffic for unusual activity.
Update LiteLLM and follow security advisories for exposed gateways.
Audit logs for unfamiliar outbound connections.
Limit internet exposure of AI services where possible.
The cryptomining family known as PoeLLM has infected more than 3,400 victim servers in a campaign named Canto Incognito. Researchers from Lumen’s Black Lotus Labs say the attackers hide the command-and-control address inside a four-word, two-stanza poem hosted on GitHub. The four words are decoded to an IPv4 address, and that address has shifted multiple times, up to 11 changes so far, so infected hosts point to new C2 servers as the operation evolves.
Most of the affected machines appear to run vulnerable versions of open-source AI tools, including LiteLLM and Ollama, even though LiteLLM issued a fix for a related vulnerability earlier this year. The malware payload includes crypto miners linked to Kryptex, and infected servers can also act as scanners for additional compromises, expanding the attacker’s reach within a network.
Early indicators tie the operation to a financially motivated effort. The campaign showed connections to an endpoint associated with a Russian cryptocurrency mining service, suggesting the attackers’ aim is to monetize compromised hardware and access. Lumen notes that, at the time of reporting, the PoeLLM C2 servers remained blocked off from many parts of the internet, complicating detection and takedown efforts.
Targets highlighted by researchers include LiteLLM, a proxy that routes calls to multiple AI models, and Gotenberg, a Docker-based API for PDF conversion. Ollama and Gitea, a self-hosted Git service, were also affected. Ivanti Sentry, an enterprise gateway device, may have been impacted as well. The big picture: attackers are exploiting publicly exposed AI services to gain footholds, then weaponizing affected machines for mining and further reconnaissance.
What this means for everyday users is simple: exposed AI tools on the internet can become entry points for criminals who monetize compromised hardware. The poem-based C2 trick is just one example of how attackers can stay flexible as they switch targets and infrastructure.
What to do now is straightforward. If you operate any of the affected tools or host AI services online, review what is exposed to the internet, scan logs for unusual outbound connections, and apply the latest security advisories for vulnerable software. Patch systems promptly and close unnecessary ports. Specifically, ensure LiteLLM installations are up to date and follow advisories from your security teams about Ivanti Sentry and other exposed gateways. Keep an eye on outbound traffic for unfamiliar destinations and regularly audit your network for signs of mining software or other unusual compute tasks.
As AI infrastructure grows, so do the opportunities for misuse. This campaign highlights the need for ongoing patching, tighter exposure controls, and vigilant monitoring to stop attackers before they pivot to new targets.
If you want to check your own setup, start by scanning for publicly exposed AI services and reviewing logs for unexpected outbound traffic. Apply patches, reduce exposure, and keep devices and gateways updated with the latest protections from your security teams.
A new wave of calendar-based phishing invites is infiltrating work and personal calendars, fooling users into revealing login details or paying bogus charges.