Report
PoeLLM malware reportedly hits more than 3,400 servers in crypto-mining campaign
DailyDarkWeb, citing Lumen’s Black Lotus Labs, says four keywords in a GitHub poem reveal the malware’s command-server address.
TLDR
DailyDarkWeb, citing Lumen’s Black Lotus Labs, reports that PoeLLM has infected more than 3,400 servers since April 2026, mostly vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments. The malware uses keywords in a GitHub poem to find its command server. Infected hosts mine cryptocurrency and scan for new victims. Lumen says a vulnerable LiteLLM endpoint was likely an exploitation path.
Combined views
1.9K
2 Sources, first seen ago
6 likes3 reposts