logo

Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping

ID: a31d3092-a346-5343-9989-84140d5765f0

STIX ID: report--a31d3092-a346-5343-9989-84140d5765f0

Feed Name: Socket Blog

Threat Score
80/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Sarah Gooding

...
...

**Executive summary:** A Shai-Hulud worm infection of a Suno developer machine led to harvested GitHub and cloud credentials being exfiltrated to public GitHub repos, enabling a threat actor (ellie.191) to access and publish Suno source code, customer records, and payment-related data; leaked code and dataset comments also confirm mass scraping of multiple music platforms. The incident is part of a broader, active supply-chain campaign that has republished malicious packages across npm, PyPI and Packagist and includes variants with destructive fallbacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.