No doubt. suno.com is malicious. Don't use it or harden your OS to the max.
After all, it is getting clear. Every device that had contact to suno.com with my login as a premium customer (world can be so weird) my new device, got infected. Almost instantly. That is a point to remark, humans are not that fast. So I think it may be Claude Code or similar that is used for attacks.
As I installed OpenSnitch (they have bugs documented), immediately I found that logs have been deleted, app refused to restart and so on.
With suno, my uBlock Origin rules block any script and URL not needed for the website to work. Additionally you may block DNS spoofing of URLs that don't need DNS on UDP port 53, which is nothing else than spoofing. goto.suno.com, auth.suno.com, cdn-o.suno.com and studio-api-prod.suno.com are at the one definitely needed to get a working website. Probably add cdn1.suno.com and cdn2.suno.com if needed for inspection at your own risk.
The attack flow is:
- JS attack, grabing your devices, don't ask for permission
- attack the device vulnerabilities and gain root access
- if they get root access: YOU ARE LOST
- attack the device vulnerabilities and gain root access
This explains how they convinced my router to be a member of a multicast group 224.0.0.1 where they controlled 224.0.0.22 to cast everything to their preferred recipients. Something like add group member 224.0.0.1 I saw in Wireshark. With one laptop and one router, where laptop (fixed address in the router) never asks about devices in the internal network, there is absolutely no need for internal multicast.
On Windows they choose Intel Software to open consoles with admin rights. On Unix, different flavors I could watch. First attack point is CUPS, the printer steering. If CUPS is not available they test each device and try to get in. And they get in. Problem is, in OpenSource all bugs are well documented, easy to find for an AI.
Anyone remembers Blue Screens under Windows? Mostly caused by device drivers not properly designed and manufactured.
After I restricted the firewall to TCP 80/443 I could see how the attacker uses UDP 53 to exchange informations with outside tunneling it over 443 HTTPS. Hardware is a wonderful thing. You just unplug the cable.
Lessons learned
- if you're target by suno, ANY DEVICE IS LOST, if you use the website suno.com
- scripts come directly from suno.com, no way to block without losing the functionality
Mitigations
You may gain time enough to create a song on suno, download it and find a way to transport the media file without using your equipment directly, it will take you at least ten minutes. This is a huge attack vector. Especially with an AI as enemy.
Sorry to say so, but there is no way to make your system safe enough. Software has vulnerabilities. Every software. Only a question of time to find these.
What you may do to gain time is:
1st rule: Never connect to suno before you have finished your setup!
- using an onion system
- disable root logins
- harden the kernel
- harden the sudo admins
- in the extreme every device would have a specialized admin
- limit the user to be the victim
- create a fake user based on this account (e.g. fireJail)
- give the fake user no device access apart keyboard and mouse
- install every application the user needs with flatpak as sandboxed application
- allow the fake user to install a flatpak sandboxed fake VM in his environment (docker has access to the kernel, not safe)
- disallow the fake VM to access any other device than mouse and keyboard (this devices have to be watched)
- disallow copy & paste or shared drives
- only install a browser with javascript sandbox, if possible (any application more is an attack vector)
- copy monitoring and audit tools to the fake user
- install monitoring and audit tools in the VM
- on any alarm, panic mode, set firewall to panic mode, stop immediatly the VM, shutdown, restore the VM to installation state
- after every suno access, reset the VM to installation state
- if installation state is still clean, otherwise throw the VM away (so it is clever to have template to create the VM)
Usage possibilities to limit time on suno.com:
- prepare the content for a song
- open suno, paste it, verify create song is working
- leave and reset VM
- come back later to fetch the song media files
- keep every visit as short as possible
Does this sound paranoid? Yes, of course. But if you are a paying premium customer and get attacked, only on that devices where I connected to suno.com (my other devices are still clean and working), there is no other way. Or like someone said, to be paranoid doesn't mean that somone is not tracing you.
Summary
- Every software is vulnerable
- Safety is a concept not reality
- who needs a security chain that is breakable at the root?
- 2-factor is nice, but not safe, especially if you need an app
- If you can't trust your device anymore, reset it
- backup may help if you know for sure, the backup is clean
- No password safes, use pen and paper
- with root access of an attacker your passwords are just burned if stored in a password manager
- use 2-factor wherever you can, that use native device capabilities without an app (like SMS for phones)
- Zero trust in the internet is not enough
- with companies attacking their own customers (suno is only one of this mafia) you have reason to get paranoid
Nice extras
As they behave like rappers that try to be someone without being it, they left their marks.
Those pictures I found in the longterm memory of the AI that are not in my song collection:

Hey they try now to be member of my .home Domain. Hmm, not by accident I suppose.

Currently I found this picture in the aura section of the AI, seems like one of the co-founders of suno. No one at suno had until now the balls to just contact me!
