cd /news/ai-safety/poellm-turns-exposed-ai-and-develope… · home › topics › ai-safety › article
[ARTICLE · art-146928] src=runtimewire.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

PoeLLM turns exposed AI and developer servers into miners and attack launchpads

Lumen's Black Lotus Labs reported that PoeLLM, an ELF malware file named libgcrypt, has infected more than 2,100 internet-exposed servers running AI and developer tools including LiteLLM, Ollama, Gotenberg and Gitea, using them to mine cryptocurrency and scan for new victims, according to BleepingComputer's October 7th report. The campaign has been active since at least April 2026, targeted systems in the United States and Western Europe, and had as many as 800 infected systems active on a single day, with Black Lotus Labs assessing with moderate confidence that the unidentified operator may be Italian. PoeLLM scans ports 3000 and 4000 and attempts an exploit involving CVE-2026-42271, a LiteLLM flaw affecting MCP server test endpoints that Horizon3 found could be chained with CVE-2026-48710, a Starlette Host-header validation bypass, to reach unauthenticated remote code execution in LiteLLM versions 1.74.2 through 1.83.6.

read4 min views1 publishedOct 7, 2026
PoeLLM turns exposed AI and developer servers into miners and attack launchpads
Image: Runtimewire (auto-discovered)

Lumen's Black Lotus Labs says the campaign compromised more than 2,100 servers, using infected machines to scan for more victims and attempt a LiteLLM exploit.

        By [RuntimeWire Staff](https://runtimewire.com/author/runtimewire-staff)
        · Published 

Primary source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/)

Why it matters #

PoeLLM shows how an exposed AI or developer service can become both a mining resource and a staging point for further attacks. The reported infection total is Black Lotus Labs' estimate, and attempted exploitation should not be mistaken for confirmed compromise of every targeted LiteLLM host.

PoeLLM has infected more than 2,100 internet-exposed servers and used them to mine cryptocurrency and search for further victims, according to research from Lumen's Black Lotus Labs, reported by BleepingComputer on October 7th. The infected systems include hosts running AI tools such as LiteLLM and Ollama, alongside Gotenberg and Gitea.

The count is Black Lotus Labs' estimate, based on its own tracking. Researchers said PoeLLM had as many as 800 infected systems active on a single day. That peak measures simultaneous activity, not the campaign's total reach. The operation has been active since at least April 2026 and has targeted systems in the United States and Western Europe.

The campaign's operator remains unidentified. Black Lotus Labs assessed with moderate confidence that the operator may be Italian, citing comments in the malware and an Italy-based server hosting an administrative interface. That assessment is not a confirmed attribution.

A poem doubles as a control panel

The malware, an ELF file named libgcrypt, hides its command-and-control address in a poem titled "On the Nature of Connection." It retrieves four words or phrases from a dash.css file in a GitHub repository that appears to be a Node.js fork, then uses a hard-coded dictionary to turn those words into numbers and construct an IPv4 address.

The arrangement lets the operator change the malware's command-and-control address by editing the poem. Black Lotus Labs reported that researchers had observed 11 poem modifications. BleepingComputer also reported that the campaign had spun up at least 11 command-and-control servers. Those are separate observations, and the report does not establish a one-to-one relationship between each poem change and a server.

Infected machines can use the changing address to keep finding the operator's infrastructure. The malware also includes remote-shell access, XMRig and Iron cryptocurrency miners, web scanning and exploit-deployment functions. Black Lotus Labs found victims communicating with Kryptex, a Russian cryptocurrency-mining service.

Infected hosts become part of the search

PoeLLM uses compromised servers to scan ports 3000 and 4000, which the researchers associate with Gotenberg and LiteLLM, and to attempt an exploit involving CVE-2026-42271. Each successful infection can provide computing capacity for mining and a new vantage point for finding other vulnerable systems.

The LiteLLM flaw affects MCP server test endpoints. It was initially disclosed as requiring authentication. Horizon3's analysis found that CVE-2026-42271 could be chained with CVE-2026-48710, a Starlette Host-header validation bypass, to reach unauthenticated remote code execution in affected deployments. Horizon3 says LiteLLM versions 1.74.2 through 1.83.6 are affected when the dependency tree includes vulnerable Starlette versions; its guidance calls for LiteLLM 1.83.7 or later and Starlette 1.0.1 or later.

Black Lotus Labs reported that PoeLLM attempts the exploit, but that finding does not establish that the exploit succeeded on every infected or targeted system. Administrators should treat evidence of scanning and attempted exploitation as a risk indicator, not proof that every exposed installation was breached through this vulnerability.

Mining capacity and exposed entry points

Black Lotus Labs says exposed AI deployments attract attackers because they can be poorly configured and run on powerful GPU systems suited to mining. PoeLLM's reported activity also includes scanning for other systems and attempting additional exploits. Researchers found vulnerable router administration interfaces on several command-and-control servers, suggesting the operator reused compromised routers, though the report does not establish how those routers were obtained.

RuntimeWire's September 25th report on an AI-assisted attacker that stole card records described a different use of AI. PoeLLM targets exposed infrastructure running AI and developer tools; researchers do not say the malware itself uses AI. Here, GPUs supply computing capacity, while internet exposure provides a route into systems.

Operators should patch exposed services, keep critical interfaces off the public internet where possible, restrict access to trusted IP addresses, and review network logs against Black Lotus Labs' indicators of compromise. Horizon3's report also recommends checking for suspicious requests to LiteLLM's MCP test endpoints and unexpected subprocess execution.

── more in #ai-safety 4 stories · sorted by recency
openalternative.co · · #ai-safety
IronClaw
── more on @poellm 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/poellm-turns-exposed…] indexed:0 read:4min 2026-10-07 · —