socket-dev · Crawled Jul 16, 2026
Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping
3 IoCs 1 Malware
Read original article ↗
AI Summary
AI music generator Suno suffered a breach stemming from the Shai-Hulud worm, which compromised a developer's machine and exfiltrated GitHub and cloud credentials. The attacker, using the handle ellie.191, accessed Suno's source code, customer data, and payment information without the company's public notification. The breach highlights the ongoing impact of the Shai-Hulud campaign, which spreads via trojanized npm, PyPI, and Packagist packages and exfiltrates credentials to public GitHub repositories.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 19 techniques
T1021.003 Distributed Component Object Model · Lateral Movement T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071 Application Layer Protocol · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1081 T1081 T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195 Supply Chain Compromise · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1485 Data Destruction · Impact T1528 Steal Application Access Token · Credential Access T1530 Data from Cloud Storage · Collection T1552 Unsecured Credentials · Credential Access T1553 Subvert Trust Controls · Defense Evasion T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access