Announced 7 Oct 2026 · Sources checked
What did Black Lotus Labs publish?
The 7 October report is titled “Canto incognito: tracking the PoeLLM malware.” We opened it on 8 October. There is no visible byline date; the HTTP Last-Modified header is 16:52:52 GMT on Wednesday 7 October. Matt Kapko’s same-day CyberScoop piece treats that as the publication day and quotes Ryan English, an information-security engineer at the lab.
Lumen says the malware targets exposed AI and open-source services — primarily LiteLLM, Ollama, Gotenberg and Gitea, with possible Ivanti Sentry targeting. The campaign is described as financially motivated: XMRig and Iron miners, Kryptex infrastructure, and infected hosts reused as scanners and exploit servers. The lab says it has blocked PoeLLM C2 traffic and that Lumen Defender customers have been protected since discovery.
That is a threat-intelligence report about internet-facing AI and developer tools, not a product launch and not a claim that a frontier chat model was jailbroken. It sits closer to ProjectDiscovery’s backdoored coding-agent demonstration than to a model-card update: the useful object is an exposed service with a known flaw, not a prompt that talks a language model into misbehaving.
How does the poem become a C2 address?
Lumen says a GitHub user named ejejejdfbbebe forked the nodejs.org website source and, in a file called dash.css that is not in the original repository, placed a two-stanza poem titled “On the Nature of Connection.” The first commit is dated 13 April 2026. The poem has been updated 11 times. The malware, the lab writes, has no other connection to Node.js.
The mechanism is a lookup, not a conversation with a model. Selected words are matched to numbers in a dictionary hard-coded in the malware and combined into the current C2 IPv4 address. When the operator wants a new C2, the keywords change and infected hosts recalculate the destination. English told CyberScoop that, without the malware, the file looks like a poem — no download links, no obvious ciphertext — and that many of the C2 addresses never appeared on crowd-sourced blocklists.
That is the opposite of prompt injection, where the malicious instruction arrives in text a model is asked to follow. PoeLLM does not need a model to read the poem. The verse publishes four numbers on a trusted host and rotates them without a new binary. We are not reprinting the verse, the dictionary, or Lumen’s worked example.
Which services does Lumen say were hit?
Most victims, the lab writes, ran vulnerable LiteLLM or Ollama. Hundreds more ran Gotenberg, an open-source PDF converter, or Gitea. Other commercial software “may also have been targeted, including Ivanti Sentry.” Lumen says it first saw the infrastructure in early June while investigating an Ivanti Sentry flaw it identifies as CVE-2026-10520. We have not opened an Ivanti advisory; that identifier is Lumen’s citation.
A sample Lumen reviewed referenced the LiteLLM path /mcp-rest/test/connection, which the lab calls “likely the exploitation path” for CVE-2026-42271. GitHub’s advisory, opened as structured JSON on 8 October, describes authenticated command execution on two MCP test endpoints: a valid proxy API key was enough, including a low-privilege internal-user key, with no admin role check. The vulnerable range is 1.74.2 up to, but not including, 1.83.7. The v1.83.7-stable release is timestamped 19 April 2026 and requires PROXY_ADMIN on those routes. We did not send a request to a LiteLLM host, and Lumen does not say how the operator obtained keys.
Gotenberg’s installation page, which Lumen screenshots and which we opened, leads with “Don’t expose Gotenberg to the public internet. Treat it like a database.” Lumen says default ports 3000 and 4000 — Gotenberg and LiteLLM — were the primary scan targets.
What do the victim numbers actually say?
The key-takeaways list says more than 3,400 victim servers, with peak activity exceeding 800 active servers a day, mostly in the United States and Western Europe. The body says almost 2,200 affected servers at the mid-June peak and repeats “almost 2,200” as the total since April, with almost 800 active a day at peak. CyberScoop repeated the 3,400 figure. We are reporting both numbers as Lumen’s.
Lumen dates the first GitHub commit to 13 April 2026, describes April traffic as a test, and says broader scanning against LiteLLM and Gotenberg began in May. Infected servers became extra workers. A chart captioned April–September 2026 is described as peaking in late June and early October. Recent hits on SSH and other login portals are called possible brute-force experiments; Lumen says many targets were dedicated servers in Italy and that the capability is immature.
Attribution is moderate-confidence. Lumen cites Italian comments in the sample, an early C2 contact with an Italy-hosted malwarescan[.]xyz server, and later C2s talking to an Italy-geolocated host it treats as an admin interface. English told CyberScoop the lab does not know how many people are involved and has not tied the activity to another named group.
| Lumen statement | Where it appears | Independent check |
|---|---|---|
| More than 3,400 victim servers | Key takeaways | Not independently scanned |
| Almost 2,200 victim servers | Body, twice, including the mid-June peak | Not reconciled with the 3,400 figure |
| Peak of almost 800 active servers a day | Key takeaways and body | Not reproduced from netflow |
What can operators do without a new exploit?
Lumen’s mitigations are operational: inspect logs against the published indicators, stop publishing default ports, and patch routers and other edge devices. The report says several C2 hosts were vulnerable routers rather than rented servers. That is the same hygiene as agent sandboxing: an AI service that is reachable from the public internet is a host, not a chat window.
For LiteLLM the patch line is still 1.83.7 or later. If you cannot upgrade, the advisory’s workaround is to block the two MCP test routes at a reverse proxy. For Gotenberg the vendor line is: do not expose it. Lumen does not name a CVE for Ollama or Gitea in the paragraphs we reviewed.
The lab published a 12-address C2 list and a matching GitHub IOC file, last updated at 16:23 UTC on 7 October, about half an hour before the blog’s Last-Modified stamp. Three addresses were still active at publication. We are not reprinting the list. Take indicators from Lumen and re-check the file; the lab says it updates that repository.
What this report does not establish
It does not establish that a language model was jailbroken by poetry, and it does not say LiteLLM, Ollama, Gotenberg or Gitea shipped a backdoor. English told CyberScoop the malware could be used to abuse models on a victim host and that the operator has built “a private army of AI-enabled proxies.” Those are his characterisations, not a measured case of model theft we can inspect.
The 3,400 and 2,200 figures sit on the same page. Until Lumen explains the difference, neither should be treated as a settled total. This article stops at the published mechanism, the named services, the April LiteLLM fix, and that unresolved count.
Common questions
Is PoeLLM an adversarial-poetry jailbreak?
No. Lumen describes a GitHub-hosted poem whose keywords are mapped to a C2 IPv4 address by a dictionary inside the malware. The exposed service is the victim, not a model decoding the verse.
Did Lumen count 3,400 victims or 2,200?
Both. The key-takeaways block says more than 3,400 victim servers. The body says almost 2,200, including at the mid-June peak. Peak daily activity is almost 800 in both places.
Does the LiteLLM CVE mean any internet-facing proxy can be taken over?
Not on the advisory’s wording. GHSA-v4p8-mg3p-g94g describes authenticated command execution on two MCP test endpoints, fixed in 1.83.7. Lumen links one of those paths to a sample. The advisory does not say the endpoints were unauthenticated.
What to remember
PoeLLM, as Lumen describes it, is a mining-and-scanning botnet that rotates C2 addresses through a GitHub poem and lives on exposed AI and developer tools. Un-expose and patch those hosts. Do not recast the poem as a jailbreak, and do not pick a victim total until Lumen’s two figures are explained.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





