{
  "id": 12694422,
  "title": "Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers",
  "url": "https://urgent.news/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-12694422",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-07T16:01:08.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers/5301672"
  },
  "original_language": "en",
  "account": "A malware named PoeLLM, believed to have been created by an Italian attacker, has infected over 3,000 servers since April, targeting enterprise AI infrastructure to mine cryptocurrency and adding compromised systems to its botnet. This is the first recorded instance of \"adversarial poetry,\" an AI jailbreak technique that disguises harmful prompts as poems to deceive large language models (LLMs) into bypassing safety protocols.\n\nAccording to Black Lotus Labs, which has been monitoring the PoeLLM malware, the attacker might have used a poem as it serves as an ideal vehicle for hiding a critical message. The poem appears to be a harmless post on GitHub, containing no links, files, or encrypted text that would raise suspicion. However, researchers believe that the attacker cleverly encoded the IP address of a command-and-control (C2) server within the poem, making it difficult for security researchers to detect.\n\nPoeLLM malware has been active since at least April, primarily infecting servers in the US and Western Europe. At its peak, the malware infected over 800 active servers per day. The malware primarily targets vulnerable internet-facing versions of LiteLLM and Ollama, as well as PDF converter Gotenberg and software development platform Gitea. The attackers may have also targeted commercial software such as Ivanti Sentry.\n\nThe researchers attribute the PoeLLM malware to an Italian-speaking criminal, naming the campaign \"Canto Incognito.\" The malicious actor is believed to be based in Italy, with evidence pointing to the GitHub user \"ejejejdfbbebe.\" The malware deploys XMRig and Iron miners and connects victims to Kryptex mining infrastructure. Additionally, PoeLLM turns compromised machines into vulnerability scanners and exploit servers, enabling the attacker to compromise even more vulnerable systems.\n\nThe researchers' investigation indicates that the cryptojacking miscreant initially committed the adversarial poem to GitHub on April 13, within a fork of the nodejs.org website source code. The file, \"dash.css,\" contains a poem titled \"On the Nature of Connection,\" which has been updated 11 times since its initial commit. The poem itself serves as a complex command-and-control (C2) mechanism, with the malware parsing the poem to extract certain words and phrases, converting them into numbers, and then forming the IPv4 address of the C2 server.",
  "summary": "Quoth the LLM, 'More and more'",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers",
        "url": "https://urgent.news/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k",
        "published": "2026-10-07T16:01:08.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}