Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
491
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

A breach of AI music generator Suno's systems was uncovered through a leaked source code that revealed how the company scraped platforms like YouTube, Deezer, and Genius to train its models. The breach was initiated by a Shai-Hulud worm infection that compromised a Suno employee's credentials, allowing a hacker identified as ellie.191 to access Suno's source code, customer list, and Stripe payment data. This incident is part of a broader series of exposures linked to Shai-Hulud, which has affected tens of thousands of GitHub repositories. The leaked code confirms allegations by the RIAA that Suno used stream-ripping methods to gather music data, employing proxies from Bright Data for this purpose. While Suno acknowledged a security incident in November 2025, describing it as limited and rapidly contained, the breach aligns with Shai-Hulud's second wave of attacks, which republished malicious versions of npm packages and affected several platforms. Despite Suno's assurance that the leaked data primarily involved outdated code, some customers confirmed the breach and reported not being notified by the company.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 2,479 445 126 -1%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.