The era of AI infrastructure meets the era of adversarial poetry. Lumen’s Black Lotus Labs has identified a malware campaign dubbed "Canto Incognito" that has infected over 3,000 servers since April 2026. The threat actor, believed to be an Italian-speaking criminal, uses a poem hosted on GitHub to hide command-and-control (C2) instructions. This technique, known as "adversarial poetry," tricks LLMs into bypassing safety guardrails by masking malicious prompts within seemingly benign literary content. It is the first confirmed real-world application of this jailbreak technique.

The Mechanism: Hiding IPs in Verse

The malware, named PoeLLM, retrieves its current C2 server address by parsing a specific poem titled "On the Nature of Connection," located in a file named dash.css within a forked nodejs.org repository. The malware extracts four specific words or phrases from the poem using hard-coded delimiters. For instance, it looks for text between "In the silent hum of " and "," to find the first component of the IP address. These extracted strings are then converted into numbers via a built-in dictionary, reconstructing the IPv4 address of the attacker’s server. Because the repository contains no links, downloadable files, or encrypted text, it evades detection by standard security scanners and even advanced models.

Targeting the AI Stack

PoeLLM aggressively scans for and exploits vulnerable, internet-facing open-source AI tools. The primary victims are running outdated versions of LiteLLM and Ollama, but the campaign also compromises Gotenberg PDF converters and Gitea development platforms. The threat hunters initially spotted the malware while investigating an Ivanti Sentry vulnerability (CVE-2026-10520). Once infected, the servers do not just mine cryptocurrency using XMRig and Iron miners; they also become vulnerability scanners, actively seeking out and compromising additional vulnerable systems to expand the botnet. At its peak, the malware infected more than 800 active servers per day.

Security Debt in AI Deployments

This campaign highlights a critical failure in modern DevOps: the rapid adoption of AI tools without corresponding security hygiene. As enterprises integrate AI into their operations, the attack surface expands exponentially. Black Lotus Labs noted that unlike the LiteLLM supply chain compromise, which focused on a single service, Canto Incognito targets multiple AI-related services simultaneously. The researchers warned that "AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers." The financially motivated attacker has successfully leveraged this negligence to build a powerful, self-propagating botnet.

Key Takeaways

  • Adversarial poetry is now a real-world attack vector, not just a theoretical LLM jailbreak.
  • Over 3,000 servers are compromised, primarily in the US and Western Europe, running LiteLLM, Ollama, Gotenberg, and Gitea.
  • The malware uses a GitHub-hosted poem to dynamically update its C2 IP address, making static blocklists ineffective.
  • Infected machines are repurposed as scanners, accelerating the spread of the malware across the AI infrastructure landscape.

The Bottom Line

Security teams can no longer treat AI deployments as standard web servers; if you aren't patching LiteLLM and Ollama aggressively, you are funding a poet's crypto farm.