I also wrote an honeypot that emulate an Ollama instance: beside the attackers, it's funny how many people are looking for free inference. Somebody from Brazil try to use my honeypot to write to chapters of a book about traditional magic rituals. My next step is to extract the data collected by this tool to extract IoC and malicious prompts and share them with the community.
In the same scope I wrote also an Ollama scanner: it fetch from Shodan the open Ollama instances, verify that they are reachable and check if they are real sending a dummy query.