PoeLLM malware hides its command servers in a poem on GitHub and infects 3,000+ servers via LiteLLM, Ollama and other AI tools
Confirmed
The takeaway
On Oct 7, 2026 Lumen’s Black Lotus Labs described “PoeLLM” (“Canto Incognito”), a campaign that since April 2026 has infected more than 3,000 servers, mostly in the US and Western Europe, through vulnerable LiteLLM, Ollama, Gotenberg, Gitea and Ivanti Sentry installs.
Status
- Claim
Confirmed
- Our reporting
- High confidence
- Importance
- 2 of 5
- Last verified
- 8 October 2026
Your AI and this story
- GPT-6 Astra160 days after its cutoff
- Claude Opus 5.599 days after its cutoff
- Gemini 3.8 Flash190 days after its cutoff
- Grok 4.7129 days after its cutoff
None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 99 days before it.
Key facts
- 3,000+ infected servers since April 2026; deploys XMRig and Iron miners and scanning tools (The Register)
- Entry points: vulnerable LiteLLM and Ollama (AI model-serving tools), Gotenberg, Gitea and Ivanti Sentry
- C2 discovery: words from a GitHub poem, ‘On the Nature of Connection’, are mapped to numbers with a hard-coded dictionary to form IP addresses; editing the poem moves the botnet
- Attributed to an Italian-speaking criminal using the GitHub handle ‘ejejejdfbbebe’
What happened
Black Lotus Labs found the campaign while investigating an Ivanti Sentry vulnerability. The poem is not a prompt to an LLM; “adversarial poetry” here means hiding instructions in innocuous verse, a technique first described as an LLM jailbreak.
Why it matters
Self-hosted model servers such as Ollama and LiteLLM proxies are now a routine target for mass exploitation.
Sources
1 source from 1 site. Numbers match the chips in the text.
1 source: 1 press
Press
- The Register: Poetry is the new AI security threat as PoeLLM malware infects 3K+ serverstheregister.com, press
Changes
- Filed