Skip to the stories
Sunday, 11 October 2026
Saved

Next edition

14:09

Headlines

Chips & Infrastructure

PoeLLM cryptomining malware infects thousands of exposed artificial intelligence servers

A novel malware campaign targeting unpatched artificial intelligence infrastructure has compromised thousands of exposed servers to mine cryptocurrency.

FTMQ SI, written by our newsroom0 views

Share
Picture: Tom's Hardware

A new cryptomining malware campaign named PoeLLM has compromised more than 3,400 servers, Tom's Hardware reported. According to security researchers at Lumen's Black Lotus Labs, the malware primarily targets exposed artificial intelligence tools, including LiteLLM and Ollama. [1]

The attackers appear to gain access through unpatched software vulnerabilities. Tom's Hardware reported that the most likely entry point into the LiteLLM servers was a bug that has had a security fix available since April. [1]

To coordinate the attack, the PoeLLM malware locates its command and control server hidden within a poem hosted on GitHub. GitHub is a cloud platform that allows developers to store and manage code repositories. [1][4]

Once inside the system, the malware uses server resources to mine cryptocurrency. Cryptocurrencies are digital assets that rely on distributed ledger technology to execute secure transactions. [1][2]

Share

In short

  • PoeLLM malware has infected over 3,400 servers hosting exposed AI tools like LiteLLM and Ollama.
  • The malware locates its control server inside a poem hosted on GitHub.
  • Security researchers at Lumen's Black Lotus Labs identified a bug patched in April as the likely breach vector.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]Cryptomining malware that locates its control server in a GitHub poem has hit more than 3,400 servers, researchers sayTom's Hardware, 1h ago (the report this story comes from)

Background

  1. [2]Cryptocurrency on Wikipedia
  2. [3]Mirai (malware) on Wikipedia
  3. [4]GitHub on Grokipedia

Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

Earlier reports of ours on the same people and subjects.

More in Chips & Infrastructure

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.