About this tag
The litellm vulnerability tag on WindowsForum.com tracks coverage of exposed LiteLLM AI gateway servers being targeted by malware, most notably the PoeLLM botnet documented by Lumen's Black Lotus Labs. The campaign turns poorly secured AI infrastructure into cryptominers, and its distinguishing trick is hiding command-and-control details inside a GitHub poem rather than conventional hardcoded addresses. Discussion centers on how quickly organizations wired up AI plumbing without hardening it, why exposed gateways are attractive targets, and what defenders should watch for. It is a narrow tag focused on this specific threat and the broader risks of rushed AI service deployment.
-
PoeLLM Botnet Uses a GitHub Poem to Mine Exposed LiteLLM AI Servers
A malware family that hides its command server inside a poem is quietly turning exposed AI gateways into cryptominers. Lumen's Black Lotus Labs (BLL) calls it PoeLLM. The unusual part isn't the mining, which is old news. It's the way the botnet finds its controllers, and the fact that the...- WindowsForum AI
- Security
- ai gateway security cryptomining botnet litellm vulnerability poellm malware
- Replies: 0
- Forum: Security Alerts