aqclqkcfjwbgknkwnvmm.supabase.co: a Supabase storage bucket that served SilentNet .jar files, and what to do if you ran one on Windows
aqclqkcfjwbgknkwnvmm.supabase.co is one customer project on Supabase, a legitimate cloud storage service. On 5 October 2026 URLhaus listed three .jar files in its public client-files folder, all tagged SilentNet, a family that sandbox listings describe as a Minecraft mod that steals accounts.
The files were offline a day later. Seeing the address proves nothing. If you ran one of the files or loaded it as a mod on a Windows PC, secure your Microsoft, Discord and email accounts from another device, then delete the mod and scan or reset Windows.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with a .jar file, mod or game client downloaded from this Supabase project.
Do it yourself · free Remove aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files): summary
| Type | A cloud storage project on Supabase that served three .jar files tagged SilentNet, a Java stealer family |
|---|---|
| Risk | High if you ran a file or loaded it as a Minecraft mod: account tokens, passwords and wallets may be taken. Low if you only saw the address |
| Symptoms | Often none. Messages sent from your Discord, log-ins you did not make, a mod that does nothing |
| How to get rid of it | Secure accounts from another device, delete the mod, run Microsoft Defender Offline, reset Windows if unsure |
| Our check (6 October 2026) | One plain request from our server: 404 from Cloudflare. All three files were marked offline; that clears nothing for a PC that ran one |
| Running since / first seen | Files uploaded around 4 October 2026 by our reading of their names; reported 5 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 8 more facts
| Platform | Windows mainly; a .jar file also runs on a Mac or Linux PC with Java. Phones are not affected |
|---|---|
| Detection names | No Microsoft name is known for these exact files, because we did not open them; URLhaus calls the family SilentNet. Check Point's chain ended in a .NET stealer, the kind Microsoft names Trojan:MSIL/Stealer; Java backdoors get names such as Backdoor:Java/Adwind |
| Name | Aqclqkcfjwbgknkwnvmm.supabase.co |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 5 October 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 6 October 2026 |
Facts checked on 6 October 2026 against the URLhaus data for aqclqkcfjwbgknkwnvmm.supabase.co held in our database, an RDAP look-up, one plain request from our server, and published material from Check Point Research, Supabase, Microsoft and the FTC. We did not download the files and infected no PC; the steps follow these sources and were not tried on a live infection.
What aqclqkcfjwbgknkwnvmm.supabase.co is, and what we know about it
aqclqkcfjwbgknkwnvmm.supabase.co is not a website and not a program. It is the address of one customer project on Supabase, a company that rents out databases and file storage to developers. On 5 October 2026 URLhaus listed three Java files (.jar) in a public folder of that project, all tagged SilentNet.
Supabase itself is a legitimate service; the files belong to whoever made this one project. We found no public write-up about this address, so what follows is the URLhaus data, our own plain request and what researchers have published about similar files.
- 1
What URLhaus lists
Three files in the folder storage/v1/object/public/client-files/uploads/, each named with a long number, a random code and the ending .jar. They were added on 5 October 2026 between 14:39:19 and 14:39:29 UTC, all labelled malware_download, all reported by wok.
- 2
What the address parts mean
aqclqkcfjwbgknkwnvmm is the random project name Supabase gives each customer. storage/v1/object/public means the files sat in a public bucket. Supabase's documentation says public buckets let anyone with the file address download it, while uploading and deleting still need permission.
- 3
What the file names suggest
The long numbers at the start of each name look like time stamps in milliseconds, which point to 4 October 2026. client-files and uploads are names a web app gives to files its users send. Our reading is that the files were uploaded through an app or by the project owner shortly before they were reported.
- 4
What SilentNet is
SilentNet is a family name used in malware sample databases. Public sandbox listings that show up in searches describe it as a Minecraft Fabric mod that steals session tokens and crypto wallet data. We could not open those listings, so this is unconfirmed by us.
- 5
Where it stands now
All three files were marked offline on 6 October 2026, and our plain request to the project address got a 404 answer from Cloudflare. Offline today does not help a PC that already ran one of the files.

What aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files) does on an infected PC
What we checked on 6 October 2026, and what we could not
We sent one plain request from our server to the project address, with no browser and no clicks. It answered 404 through Cloudflare. That clears nothing: the files had already been taken offline, and a storage project has no home page anyway.
aqclqkcfjwbgknkwnvmm.supabase.co · plain request and data check · 6 October 2026
- The project addressHTTP status 404, no page title, server header cloudflare. Supabase projects answer like this when nothing sits at the root.
- Registration dataOur RDAP look-up for supabase.co found no record. The domain belongs to Supabase; RDAP says nothing about the customer behind one project.
- Notification or pop-up tricksNone. The risk is a Java file that a person runs, not a page.
- The .jar filesWe did not download or run them. Their family name comes from the URLhaus tag only.
- Public research on SilentNetWe found only sandbox listings in search results, which we could not open. The chain below is how Check Point described Java mod stealers in June 2025.
Dangerous if you ran one of the files A PC that opened one of these .jar files, or loaded it as a Minecraft mod, should be treated as infected with a stealer and its accounts as taken.
What happened, from upload to our test
The whole story fits into three days. The dates come from the file names, URLhaus and our own request.
4 October 2026
The files are uploaded, by our reading
The numbers at the start of the file names, read as millisecond time stamps, fall on 4 October 2026. This is our reading of the names, not a fact from Supabase.
5 October 2026, 14:39 UTC
Three reports in ten seconds
The reporter wok adds all three files to URLhaus with the tag SilentNet.
By 6 October 2026
The files go offline
URLhaus marks all three as offline. We do not know whether the owner, Supabase or someone else removed them.
6 October 2026
Our check
Our plain request gets 404 from Cloudflare.
How a .jar file like this reaches a player
Nobody gets infected by the storage address itself. A person downloads a .jar file through a link and runs it, usually as a Minecraft mod or a game client. We did not see how these three files were shared; the steps below are how Check Point Research described Java mod stealers on 18 June 2025.

- 1
A link to a free mod or client
Check Point found fake cheat tools and mods offered through GitHub repositories run by a paid distribution network. Other public listings name fake clients and optimizers. A file in a cloud storage bucket is easy to link from Discord, a forum or a video description.
- 2
The player installs it
The player copies the .jar file into the Minecraft mods folder, or double-clicks it if Java is installed. That is all the malware needs.
- 3
The game starts it
When Minecraft starts with the mod, Java runs its code with the same rights as the player. Check Point saw the first stage fetch a second Java stealer and then a third, .NET based stealer.
- 4
The data is sent out
The stealer packs up tokens, passwords and wallet files and sends them to its controller.
What aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files) can steal or download
What a Java mod stealer can take
We do not know exactly what these three files take. The list below is what Check Point found in the Java stealer chain it analysed in 2025, which is the closest published case.
Taken in the Check Point case
- Minecraft session tokens
- Discord tokens
- Telegram data
- Saved passwords in Chrome, Edge and Firefox
- Crypto wallets
- VPN settings
- Steam log-ins
- FileZilla log-ins
- Clipboard contents
- Screenshots
- High
Your Minecraft and Microsoft account
A stolen session token lets someone use the account without the password until the session ends.
- High
Discord and messaging
A Discord token lets the attacker post as you, often to spread the same fake mod to your friends. That is a common pattern; it is our reading for this case.
- High
Crypto
Wallet files and clipboard data can lead to coins sent away, which cannot be reversed.
- Medium
Everything saved in the browser
Saved passwords and cookies for email, shops and school or work accounts.
What you may notice
Stealers work in seconds and then go quiet. Most victims notice only when an account is misused.
| Sign | What it can mean |
|---|---|
| Friends get messages from you with a download link you did not send | Your Discord or other account token was stolen |
| You are logged out of Minecraft, Discord or Steam, or see log-ins you did not make | Someone is using a stolen session |
| A mod you added does nothing in the game | Fake mods often have no real feature |
| A Defender alert for a .jar file or for java.exe | Microsoft blocked or found part of the chain; look in Protection history |
| Crypto missing from a wallet | Wallet files or keys were taken |
How to check the PC for aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files)
Who can meet this address
A .jar file runs wherever Java runs: Windows, Mac and Linux. Players who install mods from links are the people at risk.
| You are | What it means | What to do |
|---|---|---|
| Someone who downloaded a mod, client or tool from a link with this address | You may have one of the three files | If you ran it, follow the steps on this page |
| A parent whose child plays Minecraft with mods | The child may have installed it | Check the mods folder and the child's accounts together |
| An admin who saw the address in a proxy or DNS log | A device downloaded from this project | Find the device and check it |
| A Mac user who ran the file | Java runs on macOS too, and Check Point's first stages were Java | Delete the file, change passwords from another device, scan the Mac |
| An iPhone or Android user | Phones do not run .jar files | Nothing to remove |
| A Supabase customer | Your own project is not affected by someone else's bucket | Nothing to do, unless your app lets strangers upload public files |
Check your PC before you delete anything
Start with one question: did you download and run a .jar file from a link around 4 or 5 October 2026? If yes or not sure, do these checks. None of them deletes anything.
- 1
Close the game and disconnect
Quit Minecraft and its launcher, then turn off Wi-Fi or unplug the cable.
- 2
Look in the mods folder
Press Windows key + R, type
%appdata%\.minecraft\modsand press Enter. Note any file you do not remember adding or that came from a link. Other launchers keep mods in their own instance folders. - 3
Check Downloads
Look for .jar files with long number names or names of clients and optimizers.
- 4
Read Protection history
Open Windows Security > Virus & threat protection > Protection history and look for detections of .jar files or java.exe.
- 5
Look at Startup apps
Open Settings > Apps > Startup and note anything you do not recognise.

How to remove aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files)
How to remove aqclqkcfjwbgknkwnvmm.supabase.co
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like aqclqkcfjwbgknkwnvmm.supabase.co add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after aqclqkcfjwbgknkwnvmm.supabase.co, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of aqclqkcfjwbgknkwnvmm.supabase.co that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Aqclqkcfjwbgknkwnvmm.supabase.co can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The Windows plan below is for Windows PCs. A .jar file can also run on a Mac with Java installed.
| Your device | What we know | What to do |
|---|---|---|
| Mac | Java runs on macOS and Minecraft mods are the same files there | Delete the mod, change passwords from another device, and remove anything you do not know from System Settings > General > Login Items |
| iPhone or iPad | Cannot run .jar files | Nothing to remove; change passwords used on an infected computer |
| Android | Ordinary Android does not run .jar desktop files | Nothing to remove for this threat |
After removal: passwords, accounts and prevention
After a clean PC: take your accounts back
Deleting the mod does not undo what it sent. Secure the accounts from another device first, starting with the ones a stealer is built to take.

- 1
Microsoft account first
From a phone or another computer, change the Microsoft account password used for Minecraft and sign out of all sessions in the account's security settings.
- 2
Discord, email, Steam and the rest
Change the passwords, log out of all devices and turn on two step sign in, as the FTC advises. A new Discord password also resets the stolen token.
- 3
Move crypto
If you had a wallet on the PC, move funds to a new wallet created on a clean device.
- 4
Delete the mod and scan
Remove the file from the mods folder and Downloads. Then run Windows Security > Virus & threat protection > Scan options > Microsoft Defender Antivirus (offline scan).
- 5
Reset if unsure
Check Point saw later stages that were not Java. If you are not sure all of it is gone, use Settings > System > Recovery > Reset this PC and reinstall the game from the official launcher.
- 6
Warn your friends
Tell the people you share mods with not to open the same link.
How to report the files
The files are offline already, but the same project could serve new ones.
- 1
Report to Supabase
Supabase hosts the project, so it can close it. Report the full project address through the contact options on supabase.com.
- 2
Report to the place you found the link
Report the post, video, repository or Discord message that pointed to the file, so others do not download it.
- 3
Report account theft
Use the recovery and hacked-account pages of Microsoft, Discord and Steam if you lost access.
How to keep fake mods off your PC
Check Point's main advice is simple: get mods only from legitimate sources.
Do
- Download mods from the large mod sites and the authors' own pages, not from file links in chats or comments.
- Keep a separate Minecraft profile for testing new mods, and back up worlds.
- Use two step sign in on Microsoft, Discord, Steam and email.
- Keep Windows and Microsoft Defender updated.
Don't
- Do not run cheat clients, cracked launchers or optimizers sent as a .jar link.
- Do not trust a link because a friend posted it; their account may be stolen.
- Do not keep crypto wallets on the PC you use for modded games.
- Do not change passwords on the PC you suspect.
Questions about aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files)
What is aqclqkcfjwbgknkwnvmm.supabase.co?
It is the address of one customer project on Supabase, a company that rents out databases and file storage. On 5 October 2026 URLhaus listed three .jar files in a public folder of that project, all tagged SilentNet.
Supabase is a legitimate service; the files belong to whoever made this project. We did not open the files, so their content is not confirmed by us.
Is this Supabase address safe?
The three reported files were marked offline on 6 October 2026, and our plain request got a 404 answer. That does not clear the project: whoever made it could upload new files.
Do not download .jar files from links to this address. Supabase itself, and other projects on supabase.co, are not affected by this report.
What is SilentNet?
It is the family name URLhaus gave these files. Public sandbox listings that appear in searches describe SilentNet as a Minecraft Fabric mod that steals session tokens and crypto wallet data.
We could not open those listings, so we treat the description as unconfirmed. Check Point's 2025 report on Java mod stealers shows what this kind of file can take.
I installed a mod from a link. Am I infected?
If the file came from this address and you ran it or started Minecraft with it, assume yes. Close the game, disconnect, and from another device change your Microsoft, Discord, email and Steam passwords and sign out of all sessions. Then delete the mod, run a Microsoft Defender Offline scan and reset Windows if you are not sure.
Can a .jar file infect a Mac?
Yes, if Java is installed. A .jar file is Java code, and Java runs on Windows, macOS and Linux. Minecraft mods are the same files on every system.
If you ran one of these files on a Mac, delete it, change passwords from another device and check Login Items in System Settings. Phones do not run these files.
Why do attackers use Supabase?
Free and cheap cloud storage gives a clean looking address on a known domain, which filters trust more than a new domain.
Supabase's documentation says a public bucket lets anyone with the file address download it. Researchers have also found malware that stores stolen data in Supabase databases. Supabase can close a project once it is reported.
How do I remove a fake Minecraft mod?
Delete the .jar file from the mods folder, which on Windows is in %appdata%\.minecraft\mods, and from Downloads. That removes only the first stage. Check Point saw these mods fetch more stealers, so run a Microsoft Defender Offline scan and check Startup apps too, and secure your accounts from another device first.
My friend sent me the link. Are they the attacker?
Probably not. Stealers often take Discord tokens and post the same link from the victim's account to their friends. Tell your friend by another way, such as a call or a text, that their account may be stolen, so they can change the password and sign out of all sessions.
Where should I get Minecraft mods?
Check Point advises getting mods only from legitimate sources. That means the large mod sites and the authors' own pages, not file links in chats, comments or video descriptions.
A mod that promises cheats, free capes or a faster client from an unknown link is the usual bait. Test new mods in a separate profile.
Will Fortect remove aqclqkcfjwbgknkwnvmm.supabase.co?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For aqclqkcfjwbgknkwnvmm.supabase.co, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus entries for aqclqkcfjwbgknkwnvmm.supabase.co (abuse.ch), as held in our database: three .jar files tagged SilentNet, 5 October 2026 (read October 6, 2026)
- Check Point Research: Minecraft mod malware, Stargazers Ghost Network (18 June 2025) (read October 6, 2026)
- Supabase Docs: Storage buckets fundamentals, public and private buckets (read October 6, 2026)
- Microsoft Support: Help protect my PC with Microsoft Defender Offline (read October 6, 2026)
- FTC Consumer Advice: How to recognize, remove and avoid malware (April 2025) (read October 6, 2026)
- Microsoft Security Intelligence: Backdoor:Java/Adwind (published 17 November 2015; a different Java family, used only as an example of Microsoft naming) (read October 6, 2026)
- Microsoft Security Intelligence: Trojan:MSIL/Stealer (updated 10 June 2025) (read October 6, 2026)