More than 3,400 servers running AI and developer tools have been compromised by a financially motivated botnet that retrieves its command-and-control address from a poem stored on GitHub. Lumen Technologies’ Black Lotus Labs, which named the broader operation Canto Incognito, reported the campaign active since at least April 2026 and still recruiting new victims as of October 2026.

How a Poem Becomes a Control Switch
The mechanism is straightforward but novel: malware parses a GitHub-hosted poem to recover the address of its command-and-control server.
PoeLLM pulls a poem from a GitHub repository stored in a CSS-named file inside a Node.js fork. It extracts four words or phrases from fixed positions, maps them against a hard-coded dictionary, converts the results to numbers, and assembles a valid IPv4 address for its current command-and-control server.
Changing selected words in the poem allows infected systems to be rerouted without touching the malware binary. Black Lotus Labs traced the first relevant commit to April 13, 2026, and found the poem revised multiple times since. Think of it like a QR code that silently changes its destination without ever looking different to whoever scans it.
Researchers labeled this technique “adversarial poetry,” but the mechanism warrants a precise description: no AI model independently read the poem and acted on it. Malware parsed the text. The risk is that attackers can exploit the trust that AI systems and operators extend to content that appears harmless.
The confirmed targeted services included:
- LiteLLM (AI gateway and proxy) and Ollama (open-source model runner)
- Gotenberg (PDF conversion)
- Gitea (code hosting and software development)
- An Ivanti Sentry appliance observed during the investigation, after a compromised unit began scanning for additional vulnerable systems
What the Botnet Does Once It’s In
Compromised servers are repurposed as cryptocurrency miners and recruitment platforms for further attacks.
Compromised servers receive the XMRig and Iron cryptocurrency miners, connecting to Kryptex mining infrastructure. GPU-equipped servers are attractive targets because the same hardware used for AI inference can generate cryptocurrency revenue for an attacker.
Infected machines also run vulnerability scanners and serve as platforms for exploitation, actively recruiting new victims. At peak, nearly 800 compromised servers were active in a single day, according to Black Lotus Labs.
Black Lotus Labs attributed the campaign with moderate confidence to an Italian-speaking operator, based on Italian-language artifacts in the malware and related GitHub pages, plus network-flow analysis. The suspected GitHub account is ejejejdfbbebe. That assessment is not a confirmed identity.
What Security Teams Should Do
Exposed AI infrastructure without authentication and access controls is the consistent factor across PoeLLM victims.
AI model runners, inference gateways, PDF processors, and code-hosting tools should not be directly exposed to the internet without strong access controls. Patch LiteLLM, Ollama, Gotenberg, Gitea, and Ivanti Sentry according to current vendor guidance.
Check outbound traffic logs for connections to mining pools or unfamiliar infrastructure. Unusual scanning activity originating from your AI servers is worth investigating immediately. Treat every external document, repository, or web page that an automated system retrieves as untrusted input. Apply application-level controls that block AI systems from acting on instructions in retrieved content without explicit authorization.
Segment GPU and model-serving infrastructure from your general enterprise network. The campaign targeted internet-exposed services, and the poem functioned as a post-compromise control mechanism. AI adoption does not rewrite the rules of basic security hygiene.




























