A threat actor has compromised more than 3,400 AI inference servers and is using them for cryptomining. The evasion technique driving the operation is new: command-and-control instructions are hidden inside poetry uploaded to public GitHub repositories. The malware, which researchers have named PoeLLM, exploits AI content safety filters by encoding operational commands in poetic meter and structure, bypassing guardrails that would flag the same content in plaintext.
How PoeLLM infects AI servers
The initial access vector is exposure: the threat actor scans for GPU-accelerated hosts running AI inference services accessible on the public internet without authentication. This targets the same class of misconfigured deployment that has made AI infrastructure an increasingly attractive target in 2026. Once access is established, the malware installs a cryptomining payload alongside a small agent that periodically fetches updated instructions.
The poem C2 channel
The novel element is how the operator updates those instructions. Rather than using a traditional C2 server, which would be identifiable and blockable, the operator maintains a public GitHub repository containing what appears to be a collection of original poetry. Each poem encodes operational commands in its structure: line counts, syllable patterns, and specific word choices that the agent parses as instructions. The content looks like creative writing to any human reviewer or automated content filter.
This technique exploits a specific property of AI safety filters: they evaluate semantic meaning, not structural encoding. A poem about rain does not trigger a malware heuristic even if it contains encoded commands. Traditional network-level C2 detection based on domain reputation, protocol analysis, or traffic volume also misses this channel because HTTPS requests to raw.githubusercontent.com are indistinguishable from normal developer activity.
Why AI servers are the target
GPU-accelerated servers running AI inference workloads are attractive cryptomining targets for two reasons. First, they have significant compute available. Second, they are frequently misconfigured: developers and researchers spin up inference endpoints quickly, often without hardening, and leave them exposed while iterating on model behavior. The economics work for the attacker even if individual hosts are reclaimed quickly.
What defenders should do
Organizations running AI inference infrastructure should audit their exposure immediately. Inference endpoints should never be reachable on the public internet without authentication. Rate limiting, network egress monitoring, and GPU utilization alerting (a sudden spike in compute use during off-hours is a classic cryptomining indicator) are the most practical detections for this campaign. For the C2 channel specifically, blocking outbound HTTPS to raw.githubusercontent.com on production AI servers is an effective mitigating control if those servers have no legitimate need to fetch from GitHub at runtime.