BlackTree Security · Infrastructure · Automation · AI

Do Not Stop at the First Host

Black Lotus Labs says PoeLLM has targeted exposed LiteLLM, Ollama, Gotenberg and Gitea since April 2026, with possible Ivanti Sentry targeting.

It reports mining, scanning and exploit delivery from compromised hosts. For defenders, that turns one service incident into a potential launch point for another.

Why the first clean-up can still fail

PoeLLM converts four words in an attacker-controlled GitHub poem into a command-and-control address; the report recorded 11 changes after 13 April.

The linked IOC file marked three addresses active on 7 October, a dated status rather than an indefinite one.

Read the numbers before ranking the risk

Lumen’s key takeaways say more than 3,400 victim servers and more than 800 active on a peak day, while two body passages retain almost 2,200. BleepingComputer records a correction from 2,100 to 3,400.

The 3,400 figure is cumulative, not simultaneous, and the source discrepancy remains unresolved. Use the figures to scope the hunt, not to manufacture a precise live total.

Test the evidence before generalising the route

One reviewed sample targeted /mcp-rest/test/connection, which Black Lotus Labs calls the likely route and links to CVE-2026-42271. That finding does not establish the route for every victim or any other service.

The report does not establish that PoeLLM used the Starlette bypass. BlackTree’s earlier LiteLLM analysis covers that bypass. It remains patching context, not proof the incidents share a campaign.

Hunt for the service that became an attacker

Lumen did not report observed data theft. That does not make credentials and tokens on a reachable host trustworthy.

BlackTree recommends the following operational checks:

  • Build an exposure inventory for every self-hosted AI, document-conversion and development service. Record the exact version, owner, listening interface and business reason for public access.
  • Search DNS, firewall, proxy and flow logs against the complete dated IOC file. Review both current and historical addresses, then investigate raw-IP traffic and unusual outbound ports from the service host.
  • Trace process ancestry. A gateway, model service, converter or development platform should not normally launch shells, downloaders, miners or broad network scanners.
  • Isolate confirmed hosts and preserve process, network, scheduled-task and persistence evidence before rebuilding. If the service could reach credentials or tokens, rotate them after preserving the evidence.
  • Patch and harden each exact product rather than assuming one LiteLLM fix covers the other services. Remove unnecessary internet exposure and include routers, firewalls and other edge devices in the containment review.
  • Check what the compromised host contacted next. If it scanned or attempted exploitation, preserve the target list, block the egress path and notify the owners of affected internal systems.

Removing a miner is not enough when the host may also have become an exploitation relay. Recovery should answer how the service was exposed, what executed under it and which systems it tried to reach.

Leave a Reply

Your email address will not be published. Required fields are marked *