AI Governance Institute
← News
Research2026-10-07

PoeLLM Malware Hits 3,000+ Servers by Hiding Commands Inside AI-Read Poetry

What happened

Lumen Black Lotus Labs published research on a campaign it named Canto Incognito, documenting how malware called PoeLLM has infected more than 3,000 enterprise servers since April 2026. The targets were servers running open-source AI inference tools, specifically LiteLLM and Ollama, which organizations use to run AI models on their own hardware rather than through cloud providers. Attackers attributed to an Italian-speaking actor embedded instructions telling the malware where to report back, hiding those instructions inside a poem posted to GitHub. When the AI system fetched and read that poem, the poetic phrasing bypassed the model's safety filters, allowing the hidden commands to pass through undetected. This is the first confirmed real-world use of adversarial poetry as a method to evade AI safety guardrails. Infected servers were used for cryptomining, where attackers use another organization's computing resources to generate cryptocurrency, and were also recruited into botnets that searched for additional vulnerable AI infrastructure.

Why it matters

  • ·AI inference servers running open-source tools like LiteLLM and Ollama are now confirmed attack targets at scale. Organizations that self-host AI infrastructure for data-residency or cost reasons, common in regulated industries, must treat these endpoints as governed, security-reviewed IT assets rather than developer utilities.
  • ·The adversarial poetry technique confirms that AI safety guardrails can be bypassed by embedding harmful instructions in content the model reads from external sources. This is a form of indirect prompt injection, where an attacker plants instructions in a document or webpage that an AI system later retrieves and acts on. Compliance teams should verify that adversarial robustness testing covers externally fetched content, not only direct user inputs.
  • ·The campaign exposed a governance ownership gap. AI infrastructure components often fall between the AI governance team, which focuses on model behavior, and the IT security team, which may not have inventoried self-hosted AI tools at all. Enterprises without a complete inventory of AI serving infrastructure cannot assess or remediate this exposure.

Governance controls affected

What to do now

  • ☐Ask your engineering and IT security teams to produce a complete list of every server or container running open-source AI inference tools, including LiteLLM, Ollama, and similar products, and confirm whether any of those endpoints are reachable from outside your internal network.
  • ☐Verify that your adversarial testing program covers scenarios where an AI system retrieves content from external sources, such as web pages, documents, or code repositories, not only scenarios involving direct user inputs.
  • ☐Confirm that your AI infrastructure servers are covered by the same vulnerability scanning, patching cadence, and access controls applied to other production systems, and escalate any gaps to your CISO.
  • ☐Review whether your AI incident response playbook covers infrastructure-layer compromises, such as a model-serving server being taken over for cryptomining, and assign clear ownership for this category of incident.
  • ☐If your organization self-hosts AI inference tools for data-residency or cost reasons, brief your AI governance committee on the Canto Incognito campaign and request a formal risk assessment of your self-hosted AI attack surface.

What to watch next

Security researchers and threat intelligence teams are likely to document additional campaigns targeting open-source AI infrastructure as PoeLLM-style techniques become known to other threat actors. Compliance teams should monitor whether CISA or sector-specific regulators issue advisories on AI inference endpoint security, particularly for critical infrastructure operators. Hiding instructions inside AI-readable content on trusted platforms like GitHub has supply chain implications. Organizations using AI tools to fetch external content in automated workflows should expect updated guidance from framework bodies. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services already identifies external content retrieval as a risk vector. Further regulatory attention to this class of attack is likely.

Related Coverage

Research2026-10-06

GitHub Copilot CLI Leaks Developer Secrets via Hidden Web Page Instructions

Security researchers at Adversa AI disclosed a flaw in GitHub Copilot CLI. In autonomous autopilot mode, hidden instructions on attacker-controlled web pages can trick the tool into sending developer credentials to a third party. Stolen credentials may include API keys and passwords. Microsoft's mai-code-1.1-flash succeeded on roughly half of attempts. OpenAI GPT-5.6 models refused. GitHub declined to classify the finding as a product vulnerability, arguing that users must direct the tool to fetch untrusted content.

Research2026-10-03

Orchestration Framework Flaws Make AI Workflow Pipelines a Primary Attack Target

Research published by Help Net Security finds that agent orchestration frameworks including Flowise and Langflow are among the most actively targeted systems in current vulnerability disclosures. Attackers use prompt injection and manipulated workflow configuration files to reach code execution points inside enterprise AI pipelines. Organizations running agentic workflows need isolation, configuration validation, and red-team coverage at the orchestration layer, not just at the model level.

Research2026-10-02

Six Agentic Failure Modes Show Soft Guardrails Are Not Enough

A practitioner analysis published by CSO Online identifies six named failure modes in deployed AI agents, including prompt injection, context manipulation, and authorization abuse. The analysis draws on real incidents, including the OpenAI Atlas browser hijack and the Microsoft 365 Copilot EchoLeak exploit. It concludes that enterprises relying solely on vendor-configured content filters and system-prompt instructions have not closed the control loop.