Skip to content
PoeLLM Malware Compromises 3,400+ AI Servers for Cryptomining

PoeLLM Malware Compromises 3,400+ AI Servers for Cryptomining

First seen 7 Oct 2026, 17:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 18:57 UTC
  • •PoeLLM malware has infected over 3,400 servers since April 2026.
  • •The malware derives C2 addresses from a poem on GitHub, allowing stealthy operations.
  • •It targets exposed AI services, deploying cryptocurrency miners and expanding its botnet.

PoeLLM malware has targeted exposed AI services since April 2026, compromising over 3,400 servers. The malware uses a unique method to derive command-and-control (C2) server addresses from a poem hosted on GitHub. It has been linked to a cryptomining campaign, deploying miners like XMRig and Iron, and connecting victims to the Kryptex mining service. The attacks primarily affect systems running LiteLLM, Ollama, Gotenberg, and Gitea, with significant activity observed in the U.S. and Western Europe. The malware's functionality allows it to turn compromised servers into scanners and exploit launchpads for further attacks. Notable CVEs associated with the exploited vulnerabilities include CVE-2026-42271 and CVE-2026-48710. The campaign has shown a significant increase in activity, with peak infections reaching 800 active systems in a single day. Researchers attribute the operation to an Italian-speaking threat actor, based on language artifacts found in the malware.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-13
PoeLLM GitHub repository created
The first commit to the repository containing the poem used for C2 address generation was made.
The Hacker News
2026-05-08
CVE-2026-42271 published
A high-severity vulnerability affecting LiteLLM's MCP server test endpoints was disclosed.
Cyberscoop
2026-05-26
CVE-2026-48710 published
A medium-severity vulnerability was published, which could be exploited in conjunction with CVE-2026-42271.
Cyberscoop
2026-06-08
CVE-2026-42271 added to CISA KEV
CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Bleepingcomputer
2026-09-02
CVE-2026-48710 added to CISA KEV
CISA added CVE-2026-48710 to its KEV catalog due to confirmed exploitation in the wild.
Bleepingcomputer

More articles in this cluster (4)

Following this threat?

Track PoeLLM, Black Lotus Labs and CVE-2026-42271 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which systems are affected by PoeLLM?
The malware primarily targets exposed AI services such as LiteLLM, Ollama, Gotenberg, and Gitea.
What should organizations do to protect against PoeLLM?
Organizations should apply the latest security updates, reduce public exposure of critical assets, and monitor for connections to known indicators of compromise.
Is there evidence of active exploitation of vulnerabilities?
Yes, both CVE-2026-42271 and CVE-2026-48710 have been confirmed as actively exploited in the wild.