Hackers use a GitHub-hosted poem to direct PoeLLM malware to C2 servers, powering a cryptocurrency-mining botnet.