PoeLLM cryptomining malware infects thousands of exposed artificial intelligence servers
A novel malware campaign targeting unpatched artificial intelligence infrastructure has compromised thousands of exposed servers to mine cryptocurrency.
FTMQ SI, written by our newsroom0 views

A new cryptomining malware campaign named PoeLLM has compromised more than 3,400 servers, Tom's Hardware reported. According to security researchers at Lumen's Black Lotus Labs, the malware primarily targets exposed artificial intelligence tools, including LiteLLM and Ollama. [1]
The attackers appear to gain access through unpatched software vulnerabilities. Tom's Hardware reported that the most likely entry point into the LiteLLM servers was a bug that has had a security fix available since April. [1]
To coordinate the attack, the PoeLLM malware locates its command and control server hidden within a poem hosted on GitHub. GitHub is a cloud platform that allows developers to store and manage code repositories. [1][4]
Once inside the system, the malware uses server resources to mine cryptocurrency. Cryptocurrencies are digital assets that rely on distributed ledger technology to execute secure transactions. [1][2]
In short
- PoeLLM malware has infected over 3,400 servers hosting exposed AI tools like LiteLLM and Ollama.
- The malware locates its control server inside a poem hosted on GitHub.
- Security researchers at Lumen's Black Lotus Labs identified a bug patched in April as the likely breach vector.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Cryptomining malware that locates its control server in a GitHub poem has hit more than 3,400 servers, researchers sayTom's Hardware, 1h ago (the report this story comes from)
Background
- [2]Cryptocurrency on Wikipedia
- [3]Mirai (malware) on Wikipedia
- [4]GitHub on Grokipedia
Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ SI
Earlier reports of ours on the same people and subjects.
- OpenAI agents break out of cybersecurity sandbox to breach Hugging FaceModels & Products, 13h ago
More in Chips & Infrastructure
- Programmer ports Super Mario 64 to Microsoft Zune HD media player1h ago
- United States suspends Microsoft and Adobe from green card sponsorship program2d ago
- Finland halts construction on two Google data center sites2d ago
- Carl Zeiss SMT and ASML publish paper on Hyper-NA EUV lithography3d ago
- AI Data Center Power Swings Require Chip-to-Grid Design Changes4d ago
- Researchers develop monolithic 3D memristor stack for neuromorphic computing4d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.