Attackers use GitHub poem to infect thousands of servers with malware
Black Lotus Labs found PoeLLM malware that derives its C2 server address from a poem on GitHub, where the words driver, diode, decryption and tick encode an IPv4 address. The Canto Incognito campaign has infected over 3,000 devices, mainly via vulnerable AI services LiteLLM and Ollama, and deploys the XMRig Monero miner.
- PoeLLM malware decodes its C2 IP address from a poem posted on GitHub
- Words driver, diode, decryption and tick map to IPv4 address octets
- Over 3,000 confirmed infections, targeting LiteLLM and Ollama services
- The poem On the Nature of Connection was updated 11 times, last in September 2026
Read next
Security