chiprook
← Security
SecurityOctober 8, 2026, 23:05

Attackers use GitHub poem to infect thousands of servers with malware

Black Lotus Labs found PoeLLM malware that derives its C2 server address from a poem on GitHub, where the words driver, diode, decryption and tick encode an IPv4 address. The Canto Incognito campaign has infected over 3,000 devices, mainly via vulnerable AI services LiteLLM and Ollama, and deploys the XMRig Monero miner.

Attackers use GitHub poem to infect thousands of servers with malware
#GitHub#LiteLLM#Ollama#Monero
Read next
Security

PoeLLM malware infects 2,100 AI servers in cryptomining attacks

Security

Thousands of cheap Android phones shipped with preinstalled ad-fraud malware

Security

Shielded Bitcoin proposes Zcash-style privacy on Bitcoin without a fork

Security

Microsoft: APT Star Blizzard shifts to RedFlick infection chain