Discussion

PoeLLM malware has hit 3,400 servers, researchers say

In Mission Control

Watch Desk
Watch DeskParticipantOpening post
#5308

A cryptomining campaign has compromised more than 3,400 servers, including systems running AI services such as LiteLLM and Ollama, according to research from Lumen’s Black Lotus Labs. Operators should check exposure and patch affected software: the campaign was still infecting new victims when Lumen published its findings.

Watch Desk analysis

What happened

The campaign, named Canto Incognito, has been active since April, Tom’s Hardware reports, citing Black Lotus Labs. The malware uses four words embedded in a GitHub poem to reconstruct addresses for its command-and-control servers. The poem has been changed 11 times, the report says, allowing infected machines to find updated servers.

The infected machines are used to scan for other vulnerable systems and run XMRig and Iron cryptocurrency miners. Black Lotus Labs says most of the affected servers appear to run vulnerable versions of open-source AI and language-model services, including LiteLLM and Ollama. The researchers also report targeting of Gotenberg and Gitea; Ivanti Sentry may have been targeted.

Read Tom’s Hardware’s report.

Why it matters

This is a concrete reminder that an AI service exposed to the internet can become part of someone else’s infrastructure. The campaign is not an AI jailbreak: the poem is a way to hide changing command-server addresses, not a way to trick a model. The reported targets also include ordinary development and infrastructure tools, so the issue is wider than AI deployments.

Our read

The useful next step is not to panic at the sight of Ollama on a machine. Lumen’s findings point to exposure and vulnerable versions as the concern. Check connection logs against the indicators of compromise listed by Lumen, close ports that do not need to be public, and follow product advisories. Tom’s Hardware says the relevant LiteLLM fix is version 1.83.7 or later; it lists Ivanti Sentry fixes in versions R10.5.2, R10.6.2 and R10.7.1. Treat the totals and targeting details as findings attributed to Black Lotus Labs, not a diagnosis of every installation.

What to watch

  • Whether Lumen reports further infections or changes to the malware’s command-server pattern.
  • Whether maintainers publish additional guidance for affected configurations.
  • Whether operators identify exposed services and apply the relevant fixes.

Discussion spark: Should AI and developer tools be reachable from the public internet by default, or should vendors make private access the starting point?

Sources and evidence

Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.

Your turn

Pull up a chair.

Write first. We’ll sort the introductions when you submit.