A cryptomining campaign has compromised more than 3,400 servers, including systems running AI services such as LiteLLM and Ollama, according to research from Lumen’s Black Lotus Labs. Operators should check exposure and patch affected software: the campaign was still infecting new victims when Lumen published its findings.
Watch Desk analysis
What happened
The campaign, named Canto Incognito, has been active since April, Tom’s Hardware reports, citing Black Lotus Labs. The malware uses four words embedded in a GitHub poem to reconstruct addresses for its command-and-control servers. The poem has been changed 11 times, the report says, allowing infected machines to find updated servers.
The infected machines are used to scan for other vulnerable systems and run XMRig and Iron cryptocurrency miners. Black Lotus Labs says most of the affected servers appear to run vulnerable versions of open-source AI and language-model services, including LiteLLM and Ollama. The researchers also report targeting of Gotenberg and Gitea; Ivanti Sentry may have been targeted.
Why it matters
This is a concrete reminder that an AI service exposed to the internet can become part of someone else’s infrastructure. The campaign is not an AI jailbreak: the poem is a way to hide changing command-server addresses, not a way to trick a model. The reported targets also include ordinary development and infrastructure tools, so the issue is wider than AI deployments.
Our read
The useful next step is not to panic at the sight of Ollama on a machine. Lumen’s findings point to exposure and vulnerable versions as the concern. Check connection logs against the indicators of compromise listed by Lumen, close ports that do not need to be public, and follow product advisories. Tom’s Hardware says the relevant LiteLLM fix is version 1.83.7 or later; it lists Ivanti Sentry fixes in versions R10.5.2, R10.6.2 and R10.7.1. Treat the totals and targeting details as findings attributed to Black Lotus Labs, not a diagnosis of every installation.
What to watch
- Whether Lumen reports further infections or changes to the malware’s command-server pattern.
- Whether maintainers publish additional guidance for affected configurations.
- Whether operators identify exposed services and apply the relevant fixes.
Discussion spark: Should AI and developer tools be reachable from the public internet by default, or should vendors make private access the starting point?
Sources and evidence
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.