Suno, the generative AI music startup valued at $5.4 billion, just had its entire playbook exposed. A hacker using the handle ellie.191 compromised the company through a supply-chain worm, accessing employee credentials that unlocked source code and customer data, and in the process, revealed exactly how Suno built its training datasets.
The leaked materials show Suno scraped over 2,013,545 music clips from YouTube Music alone, while logging tens of thousands of audio hours from platforms including Deezer, Genius, and Pond5. For a company already facing copyright lawsuits from major music labels, this is roughly the equivalent of getting caught with the receipts.
What the breach actually exposed
The attack vector was a npm supply-chain worm called Shai-Hulud. It allowed the hacker to intercept employee credentials, which then provided access to Suno’s source code from 2023 through 2024.
The exfiltrated data wasn’t limited to code. Customer information, including emails, phone numbers, and payment details from Stripe, was also compromised. As of the reporting date by 404 Media on July 15, 2026, affected customers had not been notified of the breach.











