{"slug": "poellm-turns-exposed-ai-and-developer-servers-into-miners-and-attack-launchpads", "title": "PoeLLM turns exposed AI and developer servers into miners and attack launchpads", "summary": "Lumen's Black Lotus Labs reported that PoeLLM, an ELF malware file named libgcrypt, has infected more than 2,100 internet-exposed servers running AI and developer tools including LiteLLM, Ollama, Gotenberg and Gitea, using them to mine cryptocurrency and scan for new victims, according to BleepingComputer's October 7th report. The campaign has been active since at least April 2026, targeted systems in the United States and Western Europe, and had as many as 800 infected systems active on a single day, with Black Lotus Labs assessing with moderate confidence that the unidentified operator may be Italian. PoeLLM scans ports 3000 and 4000 and attempts an exploit involving CVE-2026-42271, a LiteLLM flaw affecting MCP server test endpoints that Horizon3 found could be chained with CVE-2026-48710, a Starlette Host-header validation bypass, to reach unauthenticated remote code execution in LiteLLM versions 1.74.2 through 1.83.6.", "body_md": "# PoeLLM turns exposed AI and developer servers into miners and attack launchpads\n\n**Lumen's Black Lotus Labs says the campaign compromised more than 2,100 servers, using infected machines to scan for more victims and attempt a LiteLLM exploit.**\n\n        By [RuntimeWire Staff](https://runtimewire.com/author/runtimewire-staff)\n        · Published \n\nPrimary source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/)\n\n## Why it matters\n\nPoeLLM shows how an exposed AI or developer service can become both a mining resource and a staging point for further attacks. The reported infection total is Black Lotus Labs' estimate, and attempted exploitation should not be mistaken for confirmed compromise of every targeted LiteLLM host.\n\nPoeLLM has infected more than 2,100 internet-exposed servers and used them to mine cryptocurrency and search for further victims, according to research from [Lumen's Black Lotus Labs](https://www.lumen.com/en-us/security/black-lotus-labs.html?ref=runtimewire), reported by [BleepingComputer on October 7th](https://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/?ref=runtimewire). The infected systems include hosts running AI tools such as [LiteLLM](https://www.litellm.ai/about?ref=runtimewire) and Ollama, alongside Gotenberg and Gitea.\n\nThe count is Black Lotus Labs' estimate, based on its own tracking. Researchers said PoeLLM had as many as 800 infected systems active on a single day. That peak measures simultaneous activity, not the campaign's total reach. The operation has been active since at least April 2026 and has targeted systems in the United States and Western Europe.\n\nThe campaign's operator remains unidentified. Black Lotus Labs assessed with moderate confidence that the operator may be Italian, citing comments in the malware and an Italy-based server hosting an administrative interface. That assessment is not a confirmed attribution.\n\n### A poem doubles as a control panel\n\nThe malware, an ELF file named `libgcrypt`, hides its command-and-control address in a poem titled \"On the Nature of Connection.\" It retrieves four words or phrases from a `dash.css` file in a GitHub repository that appears to be a Node.js fork, then uses a hard-coded dictionary to turn those words into numbers and construct an IPv4 address.\n\nThe arrangement lets the operator change the malware's command-and-control address by editing the poem. Black Lotus Labs reported that researchers had observed 11 poem modifications. BleepingComputer also reported that the campaign had spun up at least 11 command-and-control servers. Those are separate observations, and the report does not establish a one-to-one relationship between each poem change and a server.\n\nInfected machines can use the changing address to keep finding the operator's infrastructure. The malware also includes remote-shell access, XMRig and Iron cryptocurrency miners, web scanning and exploit-deployment functions. Black Lotus Labs found victims communicating with Kryptex, a Russian cryptocurrency-mining service.\n\n### Infected hosts become part of the search\n\nPoeLLM uses compromised servers to scan ports 3000 and 4000, which the researchers associate with Gotenberg and LiteLLM, and to attempt an exploit involving CVE-2026-42271. Each successful infection can provide computing capacity for mining and a new vantage point for finding other vulnerable systems.\n\nThe LiteLLM flaw affects MCP server test endpoints. It was initially disclosed as requiring authentication. [Horizon3's analysis](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/?ref=runtimewire) found that CVE-2026-42271 could be chained with CVE-2026-48710, a Starlette Host-header validation bypass, to reach unauthenticated remote code execution in affected deployments. Horizon3 says LiteLLM versions 1.74.2 through 1.83.6 are affected when the dependency tree includes vulnerable Starlette versions; its guidance calls for LiteLLM 1.83.7 or later and Starlette 1.0.1 or later.\n\nBlack Lotus Labs reported that PoeLLM attempts the exploit, but that finding does not establish that the exploit succeeded on every infected or targeted system. Administrators should treat evidence of scanning and attempted exploitation as a risk indicator, not proof that every exposed installation was breached through this vulnerability.\n\n### Mining capacity and exposed entry points\n\nBlack Lotus Labs says exposed AI deployments attract attackers because they can be poorly configured and run on powerful GPU systems suited to mining. PoeLLM's reported activity also includes scanning for other systems and attempting additional exploits. Researchers found vulnerable [router](https://runtimewire.com/models/huggingface/d-s-b-router-57b4f992b70494ec) administration interfaces on several command-and-control servers, suggesting the operator reused compromised routers, though the report does not establish how those routers were obtained.\n\nRuntimeWire's [September 25th report on an AI-assisted attacker that stole card records](https://runtimewire.com/article/gambit-ai-agents-credit-card-skimmers) described a different use of AI. PoeLLM targets exposed infrastructure running AI and developer tools; researchers do not say the malware itself uses AI. Here, GPUs supply computing capacity, while internet exposure provides a route into systems.\n\nOperators should patch exposed services, keep critical interfaces off the public internet where possible, restrict access to trusted IP addresses, and review network logs against Black Lotus Labs' indicators of compromise. Horizon3's report also recommends checking for suspicious requests to LiteLLM's MCP test endpoints and unexpected subprocess execution.", "url": "https://wpnews.pro/news/poellm-turns-exposed-ai-and-developer-servers-into-miners-and-attack-launchpads", "canonical_source": "https://runtimewire.com/article/poellm-exposed-ai-servers-cryptomining-botnet", "published_at": "2026-10-07 15:26:08+00:00", "updated_at": "2026-10-07 15:48:44.746318+00:00", "lang": "en", "topics": ["ai-safety", "ai-infrastructure", "ai-tools", "mlops", "agent-protocols"], "entities": ["PoeLLM", "Lumen Black Lotus Labs", "BleepingComputer", "LiteLLM", "Ollama", "Gotenberg", "Gitea", "Horizon3"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/poellm-turns-exposed-ai-and-developer-servers-into-miners-and-attack-launchpads", "markdown": "https://wpnews.pro/news/poellm-turns-exposed-ai-and-developer-servers-into-miners-and-attack-launchpads.md", "text": "https://wpnews.pro/news/poellm-turns-exposed-ai-and-developer-servers-into-miners-and-attack-launchpads.txt", "jsonld": "https://wpnews.pro/news/poellm-turns-exposed-ai-and-developer-servers-into-miners-and-attack-launchpads.jsonld"}}