"This is a first for us," the researchers told The Register via email — referring to a piece of malware that uses a poem to steer compromised machines to their operator's command-and-control servers.
How the poem inside a forked repo directs infected servers
Researchers at Lumen's Black Lotus Labs say the threat actor hid instructions in a poem titled "On the Nature of Connection," committed to a GitHub repository that is a fork of the nodejs.org website source code. The file is named "dash.css." According to Black Lotus Labs, the malware parses that poem, extracts specific words and phrases, converts them to numbers using a hard-coded dictionary in the malware, and combines those numbers into an IPv4 address that identifies the current command-and-control (C2) server.
The lab described the exact logic. A function called "extract_poem_phrase_field" pulls three fields case-insensitively from fixed text anchors in the poem:
- Word 1: text between "In the silent hum of " and ","
- Word 2: text between "each pulse of " and " threading"
- Word 3: text between "Beyond the wall of " and ","
The fourth word is located differently: the malware finds the phrase " of distant servers," walks backward to the previous whitespace, requires the four bytes before that whitespace to be "the ", and then uses the word that follows "the " as Word 4. Those four words map to numeric values that combine into the C2 IPv4 address. Black Lotus Labs says its write-up lists all C2 IP addresses and when they were first and last seen.
PoeLLM’s payloads, scanning behavior, and scale of infection
Black Lotus Labs has tracked the campaign, which it calls Canto Incognito and which deploys malware the lab refers to as PoeLLM, as active since at least April. The attacker has infected more than 3,000 servers, primarily in the United States and Western Europe, and the campaign continues to add new victims. At its peak the malware was infecting more than 800 active servers per day.
On compromised hosts PoeLLM deploys cryptomining tools — XMRig and Iron miners — and connects victims to Kryptex mining infrastructure. Beyond cryptojacking, the malware converts infected machines into vulnerability scanners and exploit servers that broaden the attacker’s reach by seeking and compromising other vulnerable systems.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTargets and initial discovery: LiteLLM, Ollama, Gotenberg, Gitea, and Ivanti Sentry (CVE-2026-10520)
The campaign primarily abuses and scans for internet-facing, vulnerable AI systems and related services. Black Lotus Labs reports most victims were running vulnerable versions of LiteLLM and Ollama. Hundreds of victims were running Gotenberg, a PDF converter, and the Gitea software development platform. The researchers also say the attacker may have targeted commercial software including Ivanti Sentry.
Black Lotus Labs first spotted the malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. In early June 2026 a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122 and shortly after began scanning for other vulnerable devices, the lab's report says.
Attribution: Canto Incognito, an Italian-speaking operator and a GitHub account
Black Lotus Labs attributes the campaign to an Italian-speaking criminal and has named the financially motivated campaign Canto Incognito because the malicious commands are hidden in a GitHub-hosted poem. The lab points to Italian-language comments within the malware and on the attacker's GitHub pages, and says netflow it analyzed suggests the attacker is located in Italy. The researchers also note they believe the poem itself was written by AI.
The GitHub user account linked to the activity is "ejejejdfbbebe." Black Lotus Labs' timeline places the first commit of the adversarial poem on April 13; the file has been updated 11 times since that initial commit.
How Black Lotus Labs situates PoeLLM in recent incident patterns
Black Lotus Labs calls the campaign "relatively unique" for targeting multiple AI-related services simultaneously. They contrast PoeLLM with an earlier LiteLLM supply-chain compromise that, according to open sources cited by the lab, focused on a single service and impacted roughly 2,500 victims. That LiteLLM incident reportedly began with a compromised Trivy build and, per CloudSEK security researchers referenced in the report, potentially exposed more than 434,000 CI/CD pipelines worldwide.
"If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up," Black Lotus Labs wrote. By expanding the scope to multiple services, the actor has built a larger, more powerful and profitable botnet. The researchers also told The Register they expect to see more of these types of attacks in the near future, saying: "As more AI-enabled servers come online, malware like PoeLLM will continue to spread."
What this means for technologists, procurement leaders, and open-source maintainers
- Technologists and security teams: Expect malware that leverages AI-era deployments and internet-facing AI stacks (LiteLLM, Ollama) to be opportunistic; Black Lotus Labs observed PoeLLM both mining on GPUs and repurposing hosts as scanners and exploit servers.
- Procurement leaders and affected enterprises: The campaign highlights cross-product risk — the attacker exploited both open-source AI services and at least one commercial product (Ivanti Sentry, CVE-2026-10520) — so software inventories and patching priorities matter.
- Open-source maintainers (LiteLLM, Ollama, Gotenberg, Gitea): The malware's success in finding internet-facing instances underlines the importance of secure defaults, clear deployment guides, and rapid patching for exposed services.
Black Lotus Labs' analysis demonstrates a novel operational model: adversarial poetry on a public GitHub repo functioning as a mutable directory for malware C2. The lab's write-up includes listed C2 IP addresses and timestamps for researchers and defenders to review. For now, the documented facts are stark: since April a single campaign using adversarial prompts in poetic form has conscripted more than 3,000 servers into a botnet that mines cryptocurrency and seeks out fresh targets — and the researchers expect further activity as AI services proliferate.
Source: The Register — "Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers"




