BleepingComputerThursday · October 8, 2026FREE

PoeLLM malware infects exposed AI servers in cryptomining attacks

securitymalwarecryptominingai-infra

BleepingComputer reported on October 7, 2026 that malware named PoeLLM is infecting exposed AI servers in cryptomining attacks. According to the report, the campaign targets AI servers that are reachable from the internet, and the compromised machines are used to mine cryptocurrency. The source frames the activity as a cryptomining operation rather than describing other payloads or objectives. The report does not identify which AI models, frameworks, or server products are affected, nor does it specify the initial access method, the number of compromised systems, or the geographic distribution of victims. No indicators of compromise, command-and-control details, or remediation guidance are included in the provided text. The name PoeLLM is the only identifier given for the malware, and BleepingComputer is the sole source cited for the campaign. Because the excerpt is limited to the headline and a brief description, the digest is restricted to those facts: a malware family called PoeLLM, exposed AI servers as the target, and cryptomining as the observed activity.

// why it matters

Developers running internet-exposed AI servers are the target set described in the report, which links such exposure to cryptomining infections.

Sources

Primary · BleepingComputerMirror · The Hacker News
▸ Read original at bleepingcomputer.com

Like this? Get the next digest.

PoeLLM malware infects exposed AI servers in cryptomining attacks — aigest.dev