• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Suno AI was invaded by the Shai-Hulud worm, and leaked source code revealed that it scraped more than 110,000 hours of music training models from YouTube

Suno AI was invaded by the Shai-Hulud worm, and leaked source code revealed that it scraped more than 110,000 hours of music training models from YouTube

KOCPC Editor by KOCPC Editor
July 17, 2026
in Anti-Virus Software and Internet Security, Latest Technology News

Suno, the most widely used AI music generation platform, was invaded by hackers using the Shai-Hulud worm. Personal information and payment data of hundreds of thousands of users within the platform were suspected to have been stolen, but Suno did not proactively notify affected customers. But the most surprising thing is that the leaked source code revealed that the company has long grabbed massive amounts of music from YouTube Music, Deezer, Pond5 and other platforms as training materials, confirming the allegations made by the Recording Industry Association of America (RIAA) in the 2024 copyright lawsuit.

‼️ BREAKING: A hacker breached AI music company Suno using the Shai-Hulud worm and released source code showing how its training set was built:

– 113,879 hours of YouTube Music
– 62,117 hours of Pond5
– 12,287 hours of Deezer
– plus Genius lyrics and a plan to download roughly… pic.twitter.com/iSbM8EHeeQ

— International Cyber Digest (@IntCyberDigest) July 16, 2026

Source code leaked, training data available at a glance

According to well-known information security media 404 Media First disclosed and followed up by multiple media reports, the intruder used the account codenamed ellie.191 to infect the computer of a Suno employee through the Shai-Hulud worm. After stealing his GitHub and cloud service credentials, he entered the company’s internal system and took away the source code, customer list and Stripe payment information.

The leaked source code and dataset annotations record Suno’s crawling scale in detail:

  • YouTube Music:113,879 hours, internal records show 2,013,545 music clips captured
  • Pond5(Copyright Music Library): 62,117 hours
  • Deezer:12,287 hours
  • Genius (lyrics platform): 17,615 hours of genius_hq dataset
  • Jamendo, Freesound, International Music Score Library Project (IMSLP): Also within the crawling range
  • Podcast Audio: Plans to download approximately 1 million hours via PodcastIndex RSS

The program code also shows that Suno used Bright Data’s proxy server service to circumvent YouTube’s anti-crawling mechanism when crawling YouTube audio. This “stream-ripping” technique is completely consistent with the specific accusations of the RIAA in the lawsuit.

Shai-Hulud Worm: One infection certificate is enough to bring down an entire backend

Named after the sandworms in Frank Herbert’s science fiction novel “Dune,” Shai-Hulud is a self-replicating supply chain attack that broke out in the npm suite ecosystem starting in September 2025. The mechanism is to hack into npm and GitHub accounts, insert malicious code into packages that are accessible to the victim’s account, and publicly push the stolen credentials to the victim’s own GitHub repository, so that anyone can obtain this credential backup.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning in September 2025, confirming that Shai-Hulud had invaded the npm ecosystem on a large scale, with more than 1,193 infection kits and even touching CrowdStrike’s npm kit. In February 2026, the new variant added a poisoning function (SANDWORM_MODE) for the AI ​​tool chain; from April to May of the same year, the Mini Shai-Hulud version further spread to multiple package ecosystems such as PyPI and Packagist.

In Suno’s case, a developer’s compromised machine became the point of compromise for the company’s entire set of backend credentials. Socket security company pointed out that ellie.191 may have directly found the public Suno employee credentials on GitHub and gained unauthorized access, rather than being the attacker who planted the worm himself. In any case, a compromised developer account is enough for an attacker to take away the core assets of the entire company.

User information is suspected to have been leaked, Suno has not issued a notice yet

ellie.191 provided 404 Media with a sample of customer records containing email addresses, phone numbers and Stripe-related payment information for what it said were hundreds of thousands of users. After seeing their information, some customers confirmed to the media that the information was true and said they had never received any notification from Suno.

Suno confirmed the existence of the security incident in a statement, but dated the incident to November 2025, saying it was “limited in scope and quickly contained,” primarily involving outdated source code, and stressed that the company does not store Stripe’s full credit card numbers. The company further stated that in accordance with applicable privacy regulations, this incident “does not require individual customer notification” and therefore has not proactively contacted affected users.

The second wave of Shai-Hulud attacks peaked in November 2025. This attack even added a destructive backdoor that directly erased the victim’s home directory when the data could not be leaked. The timing of the Suno incident closely coincided with this wave of attacks.

RIAA lawsuit: Leaked code becomes the most powerful evidence outside the court

On behalf of Sony Music, Universal Music Group (UMG) and Warner Music Group, the RIAA filed a copyright infringement lawsuit against Suno in the Massachusetts federal court on June 24, 2024, accusing Suno of copying a large number of copyrighted recordings for model training without permission. The amount of compensation may be up to US$150,000 (approximately NT$4.87 million) per infringement.

Although Suno admitted that its training materials “may cover music protected by intellectual property rights” and publicly disclosed this on its official website in accordance with California’s AB 2013 law, it defended the accusation of YouTube scraping on the grounds of “fair use” in the lawsuit. The leaked source code confirms the RIAA’s accusations in the most straightforward way, adding direct technical evidence to the lawsuit that was previously difficult to obtain.

The lawsuit continues to heat up into 2026. In May 2026, Sony and Universal applied to the court to expand the number of works covered by the lawsuit from the original 560 to 61,026. If successful, the potential statutory compensation amount will exceed US$9 billion (approximately NT$292.5 billion). Suno also applied that same month to seal the total number of audio files used in its training materials, arguing that disclosing the number would harm commercial competition. The hack exposed the scale of the training Suno had tried to hide outside the courtroom in yet another way.

Competitor Udio has reached a settlement with Warner Music in November 2025, switching to a licensing cooperation model and obtaining a joining mechanism for artists to license their voices and images. In July 2026, Suno cited the same judge’s decision to refuse to expand the scope of the Udio case and asked the Boston court to follow suit and reject Sony and Universal’s application to expand 61,026 works. The two competitors are now on completely different paths: Udio has moved towards a licensing model, while Suno is still fighting in court.

Suno is currently valued at US$5.4 billion (approximately NT$175.5 billion), has about 100 million users, and has sufficient capital on hand. But the impact of the leaked code was far greater than any security public relations crisis. It made the company’s technical defense in court face direct rebuttal for the first time from code written by its own engineers.

Source: KOCPC Chinese

Tags: HackingShai-HuludSuno

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed Xuanjie O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology