Exposed AI tooling is now a botnet target, not a lab curiosity. Lumen's Black Lotus Labs says PoeLLM has compromised more than 2,100 servers and peaked near 800 infected hosts in a single day.
What happened
The campaign has run since at least April and picked up through 2026. The malware hides its command server address in a poem hosted on GitHub, then pulls miners and scanning tools. Victims were seen talking to the Kryptex mining service. Researchers assess, with moderate confidence, that the operator is Italian. That is an assessment, not a confirmed attribution.
Compromised hosts scan onward and try to exploit CVE-2026-42271 in LiteLLM. Horizon3 has said that bug can be chained with CVE-2026-48710 for unauthenticated code execution. Black Lotus Labs also saw signs of Ivanti Sentry targeting.
Who is affected
The reported victims are mostly in the United States and Western Europe. The common thread is an AI or developer service left on the public internet, often on a GPU host.
- LiteLLM and Ollama instances reachable from the internet
- Gotenberg PDF converters and Gitea servers in the same scan set
- Any GPU host that was stood up for a pilot and never firewalled
What to do now
Take LiteLLM, Ollama, and similar AI services off the public internet, then patch and hunt for miners.
Allow only trusted source addresses. Look for unexpected outbound mining traffic, new scanning from AI hosts, and processes that do not belong on an inference box. A cryptominer on a GPU server is also a pivot host.
Source: BleepingComputer, PoeLLM malware infects exposed AI servers in cryptomining attacks.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
- Advantest confirms PII stolen in February ransomware attack
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.