chiprook
← Security
SecurityOctober 9, 2026, 02:58

PoeLLM botnet mines crypto on AI servers via LiteLLM flaw

Lumen's Black Lotus Labs uncovered the PoeLLM botnet, which mines cryptocurrency on servers running LiteLLM, Ollama, Gotenberg and Gitea. Command-and-control addresses are encoded in a GitHub poem, and initial access came through LiteLLM vulnerability CVE-2026-42271.

PoeLLM botnet mines crypto on AI servers via LiteLLM flaw
#LiteLLM#Ollama#GitHub
Read next
Security

PoeLLM malware infects 2,100 AI servers in cryptomining attacks

Security

Attackers use GitHub poem to infect thousands of servers with malware

Security

NIO ES8 in Norwegian Mine: 90% of Traffic Went to Chinese Servers

AI

669 open-source AI agent repos ranked by activity, not stars