Malware uses poems on GitHub to infect thousands of servers
Summarised from 2 outlets · Updated 8 Oct, 17:37 · Archive
Attackers have infected over 3,000 servers using malware that decodes hidden messages from poems posted on GitHub.
Cybersecurity researchers from Lumen's Black Lotus Labs have discovered a new malware attack that uses poems posted on GitHub to instruct infected systems. The malware, called PoeLLM, has infected more than 3,000 servers. The attacker first targets vulnerable internet-facing services such as LiteLLM or Ollama and installs the malware.
Once installed, PoeLLM searches GitHub for a poem that appears to be AI-generated. The malware decodes specific words from the poem into numbers that form an IP address, revealing the location of the attacker's command-and-control server. From there it receives instructions on what to do next. Lumen's Black Lotus Labs calls this technique 'adversarial poetry' and states it has never encountered anything like it before.
The attacker appears to be of Italian origin or based in Italy, according to researchers. The method is unusual in using poetry as a delivery mechanism for malware instructions, bypassing traditional security detection methods.

How it is being reported
- 'This is a first for us': Attackers uses poem to infect thousands of servers with malwareA malware hunts for hidden messages in poems posted on GitHub.TechRadar · 8 Oct, 17:05
- Poetry is the new AI security threat as PoeLLM malware infects 3K+ serversQuoth the LLM, 'More and more'The Register · 7 Oct, 17:01
In this story: PoeLLM · Lumen's Black Lotus Labs · GitHub · Italy
This summary was written by AI from the headlines and standfirsts above, and states as fact only what at least two outlets report. How we use AI · Report a problem
Comments (0)