A botnet campaign built around a Linux malware family tracked as PoeLLM is turning exposed AI infrastructure into cryptomining muscle — and doing it with an unusually quiet trick for keeping its command-and-control (C2) channel alive.
What happened
Instead of hardcoding a C2 address that defenders can block the moment it's spotted, the operators behind PoeLLM publish a poem — titled "On the Nature of Connection" — inside a GitHub repository forked from the legitimate Node.js project's source code. The malware pulls specific words out of that poem, converts them into numbers, and assembles those numbers into the IPv4 address of its current control server. Change four words in the poem, and every infected machine calculates a brand-new C2 address on its own — no malware update required. Since the poem first appeared in mid-April, its wording has been rotated eleven times while the underlying decoding logic stayed exactly the same.
The operators reach their targets by scanning the internet for exposed AI and developer tooling — LiteLLM gateways, Ollama model servers, Gotenberg document-conversion endpoints, and Gitea instances — and sending crafted requests that trick vulnerable systems into pulling down the payload themselves. One confirmed infection path abuses a known LiteLLM command-injection flaw. Once installed, the Linux payload opens a remote shell, scans for further vulnerable hosts, delivers exploits of its own, and drops XMRig and Iron cryptocurrency miners that connect out to a dedicated mining pool. A handful of compromised hosts were also seen probing SSH and other login portals — a possible, though unconfirmed, sign the operators are experimenting with credential-guessing on the side.
Well over a thousand servers have been compromised so far, concentrated in the United States and Western Europe, and the campaign is still active.
Why it matters
This isn't a supply-chain compromise or a stolen-credentials story — it's servers that were simply reachable from the internet, running vulnerable or loosely configured AI and developer tools. As teams rush to stand up LLM gateways and self-hosted model servers, many expose them without the patch discipline or access controls they'd apply to any other production system. The poem trick isn't dangerous by itself, but it's a clean example of attackers hiding C2 infrastructure in plain sight: plain text, on a trusted platform, rotated without ever touching the malware binary that defenders might otherwise fingerprint.
What to do
- Inventory every AI-adjacent service exposed to the internet — LLM gateways, model servers, document converters, git hosting — and hold them to the same patch and access-control standard as any production system.
- Patch LiteLLM and similar gateways against known command-injection issues, and never run them with open, unauthenticated access.
- Restrict administrative and API ports for Ollama, Gotenberg, and Gitea to trusted networks only.
- Watch outbound traffic for mining-pool connections or unexpected scanning behavior coming from your own infrastructure — both are signs a host has already been drafted into someone else's botnet.
- Review SSH and other login logs for automated guessing patterns, especially from unfamiliar source hosts.
