Black Lotus Labs has documented what it calls the first real-world use of "adversarial poetry" in an attack. The malware, dubbed PoeLLM, has infected more than 3,000 servers since April, with a peak of over 800 new infections per day. Most victims were running internet-facing versions of the open-source AI tools LiteLLM and Ollama, with hundreds more running Gotenberg and Gitea; the attacker may also have targeted Ivanti Sentry.

To avoid detection, the operator hid the command-and-control address inside a poem titled "On the Nature of Connection," posted to a GitHub repository that forks the nodejs.org site. The malware extracts specific words and phrases from the poem and converts them to numbers using a hard-coded dictionary, producing the IPv4 address of the current C2 server. Updating the poem changes the C2 location, giving the attacker a stealthy way to rotate infrastructure.

Black Lotus Labs attributes the campaign, which it calls Canto Incognito, to an Italian-speaking criminal using the GitHub handle "ejejejdfbbebe." The malware deploys XMRig and Iron miners and connects victims to Kryptex mining infrastructure, while also turning compromised machines into vulnerability scanners and exploit servers. The researchers said they cannot know the attacker's intent, but the poem serves as a plausible hiding place for a malicious message because it contains no links or executable content.