AI music generator Suno was breached after a supply-chain compromise reportedly infected an employee with the Shai-Hulud worm, giving an attacker access to source code, customer records, and Stripe-related payment data. Reports said the exposed customer information included email addresses, phone numbers, and partial credit card details, while Suno described the November 2025 incident as limited and quickly contained. The company also reportedly did not notify affected customers, and said the leaked code was largely outdated and that full card numbers are not stored in Stripe.
Leaked source code allegedly showed Suno collected training audio and metadata from a wide range of services, including YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, IMSLP, stock music libraries, and podcast feeds indexed through PodcastIndex. The breach was tied to the broader Shai-Hulud campaign, a worm that steals GitHub and cloud credentials from developer environments and can expose them through public GitHub repositories after spreading via malicious package republication across ecosystems such as npm, PyPI, and Packagist.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Data from the Suno breach was reportedly added to Have I Been Pwned, indicating that more than 55 million user accounts were exposed. The dataset reportedly consisted mainly of email addresses, some phone numbers, and tens of thousands of Stripe-related records with partial payment details.
Suno acknowledged that it experienced a security incident in November 2025 and said the event was limited and quickly contained. The company stated that the exposed code was primarily outdated and that full credit card numbers are not stored in Stripe.
Analysis of the leaked source code reportedly showed that Suno scraped training data from services including YouTube Music, Deezer, Genius, stock music libraries, and podcast feeds. One report also listed sources such as Pond5, Jamendo, Freesound, IMSLP, and PodcastIndex-linked podcasts.
According to reporting on the incident, an attacker used a supply-chain attack involving the Shai-Hulud worm to obtain an employee's credentials and gain unauthorized access to Suno source code and customer data. The exposed data reportedly included email addresses, phone numbers, and partial Stripe-related payment card information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
12 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourceteiss.co.uk
Open sourcesecuritymagazine.com
Open sourcemalware.news
Open sourcecyberveille.ch
Open sourcesocket.dev
Open source404media.co
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.