Botnet uses GitHub poem to conceal command servers and mine crypto on exposed AI systems

Black Lotus Labs has detailed a campaign called Canto Incognito that has compromised more than 3,400 servers since April 2026. The malware, named PoeLLM, targets vulnerable open-source AI and large language model tools, then mines cryptocurrency and scans for additional victims. Its operators hide command-and-control addresses inside a poem hosted on GitHub, according to the researchers.
Black Lotus Labs traced Canto Incognito to April 2026. The operation has ensnared over 3,400 servers, largely in the US and Western Europe. PoeLLM exploits weak open-source AI/LLM deployments, including LiteLLM and Ollama, plus Gotenberg and Gitea. It also installs XMRig and Iron miners, links victims to Kryptex, and adds remote shell, scanning, and exploit tools.
The C2 address is encoded in a GitHub-hosted poem, "On the Nature of Connection," stored as dash.css in a repository forked from nodejs.org's source. Four fixed words map through a built-in dictionary to an IPv4 address. Eleven edits have redirected bots to new servers. Discovery began with an Ivanti Sentry flaw, CVE-2026-10520.
Organizations running exposed AI/LLM, PDF conversion, and developer tooling may face stolen compute, higher cloud bills, service disruption, and use of their systems in further attacks. Because compromised machines scan and exploit others, the campaign could expand beyond initial victims, affecting downstream users and internet stability. The GitHub poem trick may complicate takedowns, as defenders must track changing encoded addresses.