A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing applications.
Active since April 2026, the operation combines vulnerability exploitation, cryptocurrency miners and an unusual command-and-control mechanism that derives server addresses from a poem hosted on GitHub.
Victims predominantly run LiteLLM, Ollama, Gotenberg and Gitea, with possible targeting of Ivanti Sentry. Most affected systems are concentrated in the United States and Western Europe.
The research’s headline findings report peak activity exceeding 800 active servers daily, while earlier sections describe approximately 2,200 affected servers, indicating different reporting snapshots.
PoeLLM retrieves its control instructions from “On the Nature of Connection,” a poem embedded in a file named dash.css within a fork of the Node.js website repository.
Researchers found no apparent connection between the malware and legitimate Node.js software.
The malware extracts four words or phrases using fixed textual markers, then maps them through a hardcoded dictionary to numerical values.
These values become the four octets of an IPv4 address identifying the current command-and-control server.
By modifying selected words, the operator can redirect infected machines without replacing their malware. Researchers observed 11 poem updates following the repository’s initial April 13 commit.
The decoding pattern remained unchanged, allowing investigators to reconstruct infrastructure transitions.
Black Lotus Labs said in a report shared with GBhackers, while investigating a compromised Ivanti Sentry system that contacted 5.78.73[.]122 and subsequently began scanning other devices.
Further telemetry exposed widespread scanning against ports 3000 and 4000, associated with Gotenberg and LiteLLM deployments.
Successful attacks instructed targets to retrieve payloads from command servers on port 81. Infected systems subsequently communicated over ports 3778, 5001, 5002 or 9999.
One analyzed sample referenced LiteLLM’s /mcp-rest/test/connection endpoint, consistent with CVE-2026-42271.
The vulnerability affects versions 1.74.2 through versions preceding 1.83.7 and permits authenticated users, including low-privilege API-key holders, to execute commands through supplied MCP configurations.
Version 1.83.7 fixes the issue. Importantly, this is authenticated command execution, not an unauthenticated flaw.
The ELF payload, named libgcrypt, incorporates remote-shell capabilities, HTTP/S scanning, exploit deployment, and XMRig and Iron miners.
Victims contacted Kryptex mining infrastructure, including 5.180.174[.]162:8029 and 46.21.245[.]211:7029.
The initial C2 decoded from the poem was 191.37.28[.]160 and appears to have been used to test the infection process.
Compromised machines also became scanning and exploitation workers, distributing the campaign’s expansion across victim infrastructure.
Recent traffic toward SSH services and login portals suggests experimentation with distributed brute-force attacks, although researchers considered that capability immature.
Several decoded command servers exposed vulnerable Boa router administration interfaces, suggesting the operator reused compromised network devices.
Researchers did not establish direct exploitation evidence for the vulnerabilities identified on the initial Brazilian router.
Italian-language comments and infrastructure connections support an Italian-speaking operator assessment, not a confirmed nationality.
Researchers separately assessed an Italy-hosted server as a probable administrative interface with moderate confidence.
Lumen says it blocked traffic to and from identified PoeLLM command servers. Defenders should correlate the reported download paths, mining connections and scanning activity with exposed application inventories.
Gotenberg’s installation guidance explicitly warns against public internet exposure and recommends keeping the service behind a firewall.
The documentation also demonstrates localhost-only port binding, directly addressing the deployment exposure exploited by campaigns targeting publicly reachable conversion services.
| IP Address | Start Date | End Date |
|---|---|---|
| 191.37.28.160 | April 13, 2026 | May 16, 2026 |
| 89.39.253.46 | April 14, 2026 | June 24, 2026 |
| 120.224.114.212 | May 9, 2026 | September 8, 2026 |
| 5.78.73.122 | June 8, 2026 | August 22, 2026 |
| 15.204.178.28 | June 14, 2026 | August 17, 2026 |
| 92.119.165.74 | July 1, 2026 | July 23, 2026 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…