Cryptomining malware hidden in poetry infected over 3,400 servers
Lumen's Black Lotus Labs says PoeLLM, a cryptomining malware tracked since April 2026 in a campaign called Canto Incognito, has compromised more than 3,400 servers. The malware uses four words from a two-stanza poem on GitHub as address encoding to redirect hosts to new command-and-control servers. Most victims run vulnerable versions of open-source AI services such as LiteLLM and Ollama.