Lumen's Black Lotus Labs says the campaign compromised more than 2,100 servers, using infected machines to scan for more victims and attempt a LiteLLM exploit.
By [RuntimeWire Staff](https://runtimewire.com/author/runtimewire-staff)
· Published
Primary source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/)
Why it matters #
PoeLLM shows how an exposed AI or developer service can become both a mining resource and a staging point for further attacks. The reported infection total is Black Lotus Labs' estimate, and attempted exploitation should not be mistaken for confirmed compromise of every targeted LiteLLM host.
PoeLLM has infected more than 2,100 internet-exposed servers and used them to mine cryptocurrency and search for further victims, according to research from Lumen's Black Lotus Labs, reported by BleepingComputer on October 7th. The infected systems include hosts running AI tools such as LiteLLM and Ollama, alongside Gotenberg and Gitea.
The count is Black Lotus Labs' estimate, based on its own tracking. Researchers said PoeLLM had as many as 800 infected systems active on a single day. That peak measures simultaneous activity, not the campaign's total reach. The operation has been active since at least April 2026 and has targeted systems in the United States and Western Europe.
The campaign's operator remains unidentified. Black Lotus Labs assessed with moderate confidence that the operator may be Italian, citing comments in the malware and an Italy-based server hosting an administrative interface. That assessment is not a confirmed attribution.
A poem doubles as a control panel
The malware, an ELF file named libgcrypt, hides its command-and-control address in a poem titled "On the Nature of Connection." It retrieves four words or phrases from a dash.css file in a GitHub repository that appears to be a Node.js fork, then uses a hard-coded dictionary to turn those words into numbers and construct an IPv4 address.
The arrangement lets the operator change the malware's command-and-control address by editing the poem. Black Lotus Labs reported that researchers had observed 11 poem modifications. BleepingComputer also reported that the campaign had spun up at least 11 command-and-control servers. Those are separate observations, and the report does not establish a one-to-one relationship between each poem change and a server.
Infected machines can use the changing address to keep finding the operator's infrastructure. The malware also includes remote-shell access, XMRig and Iron cryptocurrency miners, web scanning and exploit-deployment functions. Black Lotus Labs found victims communicating with Kryptex, a Russian cryptocurrency-mining service.
Infected hosts become part of the search
PoeLLM uses compromised servers to scan ports 3000 and 4000, which the researchers associate with Gotenberg and LiteLLM, and to attempt an exploit involving CVE-2026-42271. Each successful infection can provide computing capacity for mining and a new vantage point for finding other vulnerable systems.
The LiteLLM flaw affects MCP server test endpoints. It was initially disclosed as requiring authentication. Horizon3's analysis found that CVE-2026-42271 could be chained with CVE-2026-48710, a Starlette Host-header validation bypass, to reach unauthenticated remote code execution in affected deployments. Horizon3 says LiteLLM versions 1.74.2 through 1.83.6 are affected when the dependency tree includes vulnerable Starlette versions; its guidance calls for LiteLLM 1.83.7 or later and Starlette 1.0.1 or later.
Black Lotus Labs reported that PoeLLM attempts the exploit, but that finding does not establish that the exploit succeeded on every infected or targeted system. Administrators should treat evidence of scanning and attempted exploitation as a risk indicator, not proof that every exposed installation was breached through this vulnerability.
Mining capacity and exposed entry points
Black Lotus Labs says exposed AI deployments attract attackers because they can be poorly configured and run on powerful GPU systems suited to mining. PoeLLM's reported activity also includes scanning for other systems and attempting additional exploits. Researchers found vulnerable router administration interfaces on several command-and-control servers, suggesting the operator reused compromised routers, though the report does not establish how those routers were obtained.
RuntimeWire's September 25th report on an AI-assisted attacker that stole card records described a different use of AI. PoeLLM targets exposed infrastructure running AI and developer tools; researchers do not say the malware itself uses AI. Here, GPUs supply computing capacity, while internet exposure provides a route into systems.
Operators should patch exposed services, keep critical interfaces off the public internet where possible, restrict access to trusted IP addresses, and review network logs against Black Lotus Labs' indicators of compromise. Horizon3's report also recommends checking for suspicious requests to LiteLLM's MCP test endpoints and unexpected subprocess execution.