chiprook
← Security
SecurityOctober 7, 2026, 22:04

PoeLLM malware infects 2,100 AI servers in cryptomining attacks

The PoeLLM malware has compromised over 2,100 exposed AI servers running LiteLLM, Ollama, Gotenberg, and Gitea, turning them into scanners and cryptomining launchpads. It retrieves C2 addresses by extracting words from a poem hosted on GitHub, and victims communicate with Russian mining service Kryptex.

PoeLLM malware infects 2,100 AI servers in cryptomining attacks
#LiteLLM#Ollama#GitHub#Kryptex
Read next
Security

ChainVeil attack hides malware in vite.config.js via forged merge commit

Security

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Security

Brevo supply chain attack injects malware into 100,000 websites

Security

World's most sophisticated malware attack reportedly now freely available on GitHub