PoeLLM Malware Hits 3,000+ Servers by Hiding Commands Inside AI-Read Poetry
Source
Poetry is the new AI security threat as PoeLLM malware infects 3K+ serversLumen Black Lotus Labs / The Register
What happened
Lumen Black Lotus Labs published research on a campaign it named Canto Incognito, documenting how malware called PoeLLM has infected more than 3,000 enterprise servers since April 2026. The targets were servers running open-source AI inference tools, specifically LiteLLM and Ollama, which organizations use to run AI models on their own hardware rather than through cloud providers. Attackers attributed to an Italian-speaking actor embedded instructions telling the malware where to report back, hiding those instructions inside a poem posted to GitHub. When the AI system fetched and read that poem, the poetic phrasing bypassed the model's safety filters, allowing the hidden commands to pass through undetected. This is the first confirmed real-world use of adversarial poetry as a method to evade AI safety guardrails. Infected servers were used for cryptomining, where attackers use another organization's computing resources to generate cryptocurrency, and were also recruited into botnets that searched for additional vulnerable AI infrastructure.
Why it matters
- ·AI inference servers running open-source tools like LiteLLM and Ollama are now confirmed attack targets at scale. Organizations that self-host AI infrastructure for data-residency or cost reasons, common in regulated industries, must treat these endpoints as governed, security-reviewed IT assets rather than developer utilities.
- ·The adversarial poetry technique confirms that AI safety guardrails can be bypassed by embedding harmful instructions in content the model reads from external sources. This is a form of indirect prompt injection, where an attacker plants instructions in a document or webpage that an AI system later retrieves and acts on. Compliance teams should verify that adversarial robustness testing covers externally fetched content, not only direct user inputs.
- ·The campaign exposed a governance ownership gap. AI infrastructure components often fall between the AI governance team, which focuses on model behavior, and the IT security team, which may not have inventoried self-hosted AI tools at all. Enterprises without a complete inventory of AI serving infrastructure cannot assess or remediate this exposure.
Governance controls affected
What to do now
- ☐Ask your engineering and IT security teams to produce a complete list of every server or container running open-source AI inference tools, including LiteLLM, Ollama, and similar products, and confirm whether any of those endpoints are reachable from outside your internal network.
- ☐Verify that your adversarial testing program covers scenarios where an AI system retrieves content from external sources, such as web pages, documents, or code repositories, not only scenarios involving direct user inputs.
- ☐Confirm that your AI infrastructure servers are covered by the same vulnerability scanning, patching cadence, and access controls applied to other production systems, and escalate any gaps to your CISO.
- ☐Review whether your AI incident response playbook covers infrastructure-layer compromises, such as a model-serving server being taken over for cryptomining, and assign clear ownership for this category of incident.
- ☐If your organization self-hosts AI inference tools for data-residency or cost reasons, brief your AI governance committee on the Canto Incognito campaign and request a formal risk assessment of your self-hosted AI attack surface.
What to watch next
Security researchers and threat intelligence teams are likely to document additional campaigns targeting open-source AI infrastructure as PoeLLM-style techniques become known to other threat actors. Compliance teams should monitor whether CISA or sector-specific regulators issue advisories on AI inference endpoint security, particularly for critical infrastructure operators. Hiding instructions inside AI-readable content on trusted platforms like GitHub has supply chain implications. Organizations using AI tools to fetch external content in automated workflows should expect updated guidance from framework bodies. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services already identifies external content retrieval as a risk vector. Further regulatory attention to this class of attack is likely.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
