A Poem on GitHub Is Telling Thousands of Hijacked AI Servers Where to Phone Home. It's Not a Jailbreak. It's a Dead Drop in Verse.
Somebody wrote a poem called "On the Nature of Connection," hid it in a CSS file in a GitHub repository, and used it to steer a botnet of hijacked AI servers. Lumen's Black Lotus Labs, who found it, call the malware PoeLLM and the campaign Canto Incognito. They have been tracking it since April, and they count somewhere between about 2,200 and more than 3,400 victim servers, with around 800 active on a busy day.
All the credit for the research is theirs. Read their write-up, Canto incognito: tracking the PoeLLM malware, and pull their indicator list. What follows is what the poem actually does, what other public feeds already knew, and what we have put in our own feed.
It's not a jailbreak
Some of the coverage is calling this "adversarial poetry," the name for the trick of wrapping a harmful request in verse to talk an AI model past its guardrails. That is not what is happening here. No AI model reads this poem. The malware reads it.
The implant downloads the poem, looks up certain words in a dictionary built into its code, and turns them into four numbers, which become the IP address of its command server. Change a few words in the poem and every infected server quietly moves to a new address. The malware itself never has to change, nothing suspicious has to be pushed to the victims, and the only thing a defender sees is a server fetching a stylesheet from GitHub.
That is a dead drop: a message left in plain sight on a platform nobody blocks. We have written about the same idea on blockchains, where malware reads its next address out of a smart contract. A poem on GitHub is the same trick in a friendlier font.
What it goes after
The targets are the boxes companies stand up to serve AI: LiteLLM proxies, Ollama model servers, Gotenberg document converters and Gitea code servers, left reachable from the internet. The way in includes CVE-2026-42271, a command-injection flaw in a test endpoint of LiteLLM's MCP server. Once inside, PoeLLM mines cryptocurrency and turns the victim into a scanner that hunts for the next exposed server.
The mining is the least of it. A LiteLLM proxy exists to hold a company's API keys for every model provider it uses, so that applications can call one gateway instead of five. Code execution on that box is code execution next to the keys to OpenAI, Anthropic, Azure and whoever else, which is metered inference that bills to the victim. This operator chose to mine with the access. The next one to find the same open port can choose to steal the keys instead, and you would find out from your invoice. Treat a compromised LiteLLM as a credential breach, not a performance problem: rotate every provider key it held.
This is the same beat as the LMCache bug we wrote about this morning, and the Monero miner that rode a Langflow bug in March. AI serving software gets deployed fast, exposed by default more often than it should be, and it sits on expensive hardware. Criminals have noticed.
What other feeds already had
We checked every indicator against our corpus and its neighbors before writing this. We held none of the bare indicators. But the graph turned up three things worth knowing, all from other people's feeds, so they are corroboration we cite, not detections we claim.
URLhaus listed files under /private/ on one command server, 5.78.73.122, on June 13, including a Linux binary tagged Mirai. Black Lotus says that server went live on June 8.
ThreatFox's records show two files on another command server, 103.249.201.108, first seen on September 19: xmrig-win.zip and rigel-win.zip. (An earlier version of this post said September 23. That was the day the records entered our own index, not the day anyone saw them. Our ingest date is not a detection date, and we should not have used it.) Both are Windows builds of cryptocurrency miners.
And two of the command servers sit inside network blocks that Spamhaus DROP has listed since February, months before the campaign used them. If you block DROP, you were covered for those two. That credit is Spamhaus's, not ours.
What we put in our feed
We added 20 indicators from the Black Lotus list, each written and then read back to confirm it landed: 16 IP addresses, the malwarescan.xyz domain and three malware sample hashes. We graded confidence by how recently each command server was active. Servers Black Lotus lists as live through October 7 are at 85 (except one that looks like a hijacked victim, held at 75), and ones that went quiet months ago are lower, because hosting addresses get reassigned to innocent customers. Everything at 30 or above ships in our default blocklists. The older addresses are below our own edge shield's blocking floor, so a subscriber pulling with a minimum confidence of 80 will not see them.
We left two things out on purpose. Kryptex is a commercial mining pool, not the attacker's infrastructure, and blocking it is a policy decision for you, not a threat indicator from us. The GitHub account that hosts the poem lives on github.com, and nobody should be blocking GitHub.
We hunted the shape, not the poem
The poem is burned: the GitHub account that hosted it now returns a 404, and the Wayback Machine never captured it. So we stopped looking for the words and looked for the shape the operator will probably reuse.
The first half of the shape is the drop itself: a fork of the nodejs.org website repository, a throwaway keyboard-mash username, and a CSS file the upstream project does not have, holding sentences instead of style rules. We checked every fork of nodejs.org created since March that had commits of its own, 61 of them, for added CSS files or prose inside CSS. None matched. If there is a second drop, it is not in that repository.
The second half of the shape is how the command servers hand out payloads: every one we could see served files from port 81 under a folder called /private/. Searching our corpus for that layout turned up two servers that Black Lotus did not list. Both, 165.245.138.247 and 217.76.63.67, served the same xmrig-win.zip and rigel-win.zip files as a listed command server. The same ThreatFox contributor, adamivie, reported all three within two seconds of each other on September 19, and tagged them as a cryptojacking botnet going after ComfyUI, the popular image-generation tool, under the name "sparky." We could not find a published campaign by that name. That is a second set of eyes on the same servers, under a different label, nineteen days before the Black Lotus report, and it suggests the campaign reaches ComfyUI servers too, which the report does not list. Today the first shows nothing but SSH. The second still has port 81 open as a public directory, plus port 4000, which is LiteLLM's, and port 5001, one of the ports PoeLLM bots call home on. We added both to our feed below our own edge shield's blocking floor, labeled as shape matches, not confirmed members of the campaign.
The surprise was what those servers look like. One of the command servers on the Black Lotus list resolves to a company's AI automation server, with two of PoeLLM's call-home ports open. The new sibling is shaped the same way. PoeLLM does not appear to buy all of its own infrastructure. It seems to recruit hijacked AI servers into it. That changes what an indicator means here: some of these addresses are somebody's production machine, so we lowered the one that looked like a victim below our blocking floor, and we are not naming the company.
What our edge saw: nothing, and why that's not reassuring
We ran the LiteLLM exploit path against everything our edge recorded since April 1: 967,905 blocked requests, 135,691 honeypot hits and 8,180 requests that reached our servers. Zero matches. That is expected and it means nothing about your exposure. We don't run LiteLLM, and our edge only sees web traffic to our own sites. A scan of port 4000 on your inference box never passes through us.
What to do
Find every LiteLLM, Ollama, Gotenberg and Gitea instance you run and check whether ports 3000, 4000 and 11434 are reachable from the internet. If they are, put them behind authentication or take them off the internet. Patch LiteLLM against CVE-2026-42271.
Look for the symptoms: an unexpected process named libgcrypt, outbound connections on ports 3778, 5001, 5002 or 9999, GPU or CPU pinned at full load with nothing scheduled, and a server fetching a dash.css file from GitHub that has no business fetching anything from GitHub.
And pull the indicators, from Black Lotus directly or from our feed.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=poellm-github-poem-dead-drop-hijacked-ai-servers-litellm-ollama



Comments