Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping
Blog post from Socket
A breach of AI music generator Suno's systems was uncovered through a leaked source code that revealed how the company scraped platforms like YouTube, Deezer, and Genius to train its models. The breach was initiated by a Shai-Hulud worm infection that compromised a Suno employee's credentials, allowing a hacker identified as ellie.191 to access Suno's source code, customer list, and Stripe payment data. This incident is part of a broader series of exposures linked to Shai-Hulud, which has affected tens of thousands of GitHub repositories. The leaked code confirms allegations by the RIAA that Suno used stream-ripping methods to gather music data, employing proxies from Bright Data for this purpose. While Suno acknowledged a security incident in November 2025, describing it as limited and rapidly contained, the breach aligns with Shai-Hulud's second wave of attacks, which republished malicious versions of npm packages and affected several platforms. Despite Suno's assurance that the leaked data primarily involved outdated code, some customers confirmed the breach and reported not being notified by the company.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 2,479 | 445 | 126 | -1% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.