As reported by BleepingComputer, the PoeLLM malware campaign has compromised over 3,400 servers by targeting exposed AI services including LiteLLM, Ollama, Gotenberg, and Gitea. The operation, tracked by Lumen's Black Lotus Labs, demonstrates a troubling convergence: threat actors are now purpose-built tooling around the abysmal security posture of hastily deployed AI infrastructure.
What makes PoeLLM noteworthy is not its cryptomining payload — XMRig and Iron miners are commodity components — but its command-and-control architecture. The malware retrieves C2 addresses by parsing keywords embedded in a poem hosted on a GitHub repository, mapping them through a hard-coded dictionary to reconstruct IPv4 addresses. This is steganographic C2 resolution using public infrastructure, and it is designed specifically to evade static analysis and traditional IOC-based detection. Updating the C2 is as simple as editing a poem on GitHub. Security teams that rely on firewall blocklists and known-bad-IP feeds will consistently trail this operator.
Why AI Infrastructure Is the New Battleground
The targeting of LiteLLM and Ollama is not coincidental. These frameworks are being stood up rapidly by organizations racing to deploy LLM capabilities, frequently on powerful GPU clusters with minimal hardening, default credentials, and direct internet exposure. The same hardware that makes these servers valuable for inference makes them ideal cryptomining nodes. PoeLLM's operators understand this economics.
The campaign also exploits CVE-2026-42271, a vulnerability in LiteLLM's MCP server test endpoints originally rated High severity and believed to require authentication. Horizon.ai researchers confirmed it can be chained with CVE-2026-48710 for unauthenticated remote code execution. This is the pattern defenders need to internalize: authentication-required vulnerabilities in exposed services are rarely the end of the story. Chaining opportunities collapse the barrier to entry.
Vulnerability Details
| CVE | Product | Component | Severity | Authentication | Patch Status |
|---|---|---|---|---|---|
| CVE-2026-42271 | LiteLLM | MCP server test endpoints | High | Originally believed auth-required; chainable for unauth | Check vendor advisory |
| CVE-2026-48710 | LiteLLM | Chain component enabling RCE | High | Unauthenticated when chained | Check vendor advisory |
Active exploitation in the wild is confirmed. PoeLLM scanners actively probe ports 3000 and 4000 — associated with Gotenberg and LiteLLM respectively — to identify and exploit vulnerable instances.
Who Is at Risk
Shield53 Recommendations
Immediate Actions
- Patch LiteLLM immediately. Apply updates addressing CVE-2026-42271 and CVE-2026-48710. If patches are unavailable, disable or restrict access to MCP test endpoints.
- Remove AI inference services from internet exposure. Place LiteLLM, Ollama, Gotenberg, and Gitea behind VPN, zero-trust access, or reverse proxy with authentication. No AI tooling should be directly internet-reachable.
- Block and monitor scanning indicators. Watch for outbound connections on ports 3000 and 4000 from non-development hosts. Inbound scanning of these ports from unfamiliar sources should trigger alerting.
- Hunt for the libgcrypt ELF binary. The malware disguises itself as a legitimate cryptographic library. Look for unexpected libgcrypt binaries in process lists, especially on GPU-enabled hosts.
- Inspect GitHub repository forks. The C2 mechanism uses a GitHub repo that appears to fork Node.js and hosts a poem in a dash.css file. Monitor for connections to unfamiliar GitHub raw content endpoints from server infrastructure.
- Detect XMRig and Iron miner artifacts. Run memory and process analysis on GPU servers. Check for unexpected CPU/GPU utilization spikes, especially during off-hours.
- Review Kryptex-related network traffic. BLL identified communications with this Russian crypto-mining service. Block and alert on associated domains/IPs.
Strategic Actions
- Implement network segmentation for AI infrastructure. GPU clusters should be in isolated network zones with egress filtering. Cryptomining requires outbound connectivity to mining pools — strict egress controls are your best preventive control.
- Adopt threat-informed defense for AI tooling. The rush to deploy LLM capabilities is creating a class of infrastructure with the security maturity of early cloud adoption. Treat AI services as critical infrastructure, not experimental sandboxes.
- Build detection for steganographic C2. Traditional IOC feeds will miss this. Invest in behavioral detection: anomalous GitHub API calls, unusual file reads from public repositories, and encoded data extraction patterns.
- Inventory all exposed AI services. Many organizations do not know how many Ollama or LiteLLM instances exist in their environment. Conduct an external attack surface scan immediately.
The PoeLLM campaign is a preview of what is coming. As AI infrastructure proliferates faster than security teams can harden it, expect more purpose-built malware targeting this attack surface. The organizations that win will be those that apply the hard-won lessons of cloud security — segmentation, egress control, attack surface management — to AI infrastructure before the next campaign arrives.