aqclqkcfjwbgknkwnvmm.supabase.co: a Supabase storage bucket that served SilentNet .jar files, and what to do if you ran one on Windows

aqclqkcfjwbgknkwnvmm.supabase.co is one customer project on Supabase, a legitimate cloud storage service. On 5 October 2026 URLhaus listed three .jar files in its public client-files folder, all tagged SilentNet, a family that sandbox listings describe as a Minecraft mod that steals accounts.

The files were offline a day later. Seeing the address proves nothing. If you ran one of the files or loaded it as a mod on a Windows PC, secure your Microsoft, Discord and email accounts from another device, then delete the mod and scan or reset Windows.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with a .jar file, mod or game client downloaded from this Supabase project.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Three cards for the URLhaus entries of the Supabase project: three .jar files tagged SilentNet
The three URLhaus entries we read on 6 October 2026. There is no browser screenshot: our check was a plain request from our server, which got 404.

Aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files): summary

TypeA cloud storage project on Supabase that served three .jar files tagged SilentNet, a Java stealer family
RiskHigh if you ran a file or loaded it as a Minecraft mod: account tokens, passwords and wallets may be taken. Low if you only saw the address
SymptomsOften none. Messages sent from your Discord, log-ins you did not make, a mod that does nothing
How to get rid of itSecure accounts from another device, delete the mod, run Microsoft Defender Offline, reset Windows if unsure
Our check (6 October 2026)One plain request from our server: 404 from Cloudflare. All three files were marked offline; that clears nothing for a PC that ran one
Running since / first seenFiles uploaded around 4 October 2026 by our reading of their names; reported 5 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
PlatformWindows mainly; a .jar file also runs on a Mac or Linux PC with Java. Phones are not affected
Detection namesNo Microsoft name is known for these exact files, because we did not open them; URLhaus calls the family SilentNet. Check Point's chain ended in a .NET stealer, the kind Microsoft names Trojan:MSIL/Stealer; Java backdoors get names such as Backdoor:Java/Adwind
NameAqclqkcfjwbgknkwnvmm.supabase.co
Evidence3 write-ups by security sites; details still limited
First seen5 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked6 October 2026

Facts checked on 6 October 2026 against the URLhaus data for aqclqkcfjwbgknkwnvmm.supabase.co held in our database, an RDAP look-up, one plain request from our server, and published material from Check Point Research, Supabase, Microsoft and the FTC. We did not download the files and infected no PC; the steps follow these sources and were not tried on a live infection.

What aqclqkcfjwbgknkwnvmm.supabase.co is, and what we know about it

aqclqkcfjwbgknkwnvmm.supabase.co is not a website and not a program. It is the address of one customer project on Supabase, a company that rents out databases and file storage to developers. On 5 October 2026 URLhaus listed three Java files (.jar) in a public folder of that project, all tagged SilentNet.

Supabase itself is a legitimate service; the files belong to whoever made this one project. We found no public write-up about this address, so what follows is the URLhaus data, our own plain request and what researchers have published about similar files.

  1. 1

    What URLhaus lists

    Three files in the folder storage/v1/object/public/client-files/uploads/, each named with a long number, a random code and the ending .jar. They were added on 5 October 2026 between 14:39:19 and 14:39:29 UTC, all labelled malware_download, all reported by wok.

  2. 2

    What the address parts mean

    aqclqkcfjwbgknkwnvmm is the random project name Supabase gives each customer. storage/v1/object/public means the files sat in a public bucket. Supabase's documentation says public buckets let anyone with the file address download it, while uploading and deleting still need permission.

  3. 3

    What the file names suggest

    The long numbers at the start of each name look like time stamps in milliseconds, which point to 4 October 2026. client-files and uploads are names a web app gives to files its users send. Our reading is that the files were uploaded through an app or by the project owner shortly before they were reported.

  4. 4

    What SilentNet is

    SilentNet is a family name used in malware sample databases. Public sandbox listings that show up in searches describe it as a Minecraft Fabric mod that steals session tokens and crypto wallet data. We could not open those listings, so this is unconfirmed by us.

  5. 5

    Where it stands now

    All three files were marked offline on 6 October 2026, and our plain request to the project address got a 404 answer from Cloudflare. Offline today does not help a PC that already ran one of the files.

Three cards for the URLhaus entries of the Supabase project: three .jar files in the client-files bucket added on 5 October 2026 and tagged SilentNet
Our summary of the three URLhaus entries, read on 6 October 2026. All three were marked offline by then.

What aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files) does on an infected PC

What we checked on 6 October 2026, and what we could not

We sent one plain request from our server to the project address, with no browser and no clicks. It answered 404 through Cloudflare. That clears nothing: the files had already been taken offline, and a storage project has no home page anyway.

aqclqkcfjwbgknkwnvmm.supabase.co · plain request and data check · 6 October 2026

  • The project addressHTTP status 404, no page title, server header cloudflare. Supabase projects answer like this when nothing sits at the root.
  • Registration dataOur RDAP look-up for supabase.co found no record. The domain belongs to Supabase; RDAP says nothing about the customer behind one project.
  • Notification or pop-up tricksNone. The risk is a Java file that a person runs, not a page.
  • The .jar filesWe did not download or run them. Their family name comes from the URLhaus tag only.
  • Public research on SilentNetWe found only sandbox listings in search results, which we could not open. The chain below is how Check Point described Java mod stealers in June 2025.

Dangerous if you ran one of the files A PC that opened one of these .jar files, or loaded it as a Minecraft mod, should be treated as infected with a stealer and its accounts as taken.

What happened, from upload to our test

The whole story fits into three days. The dates come from the file names, URLhaus and our own request.

  1. 4 October 2026

    The files are uploaded, by our reading

    The numbers at the start of the file names, read as millisecond time stamps, fall on 4 October 2026. This is our reading of the names, not a fact from Supabase.

  2. 5 October 2026, 14:39 UTC

    Three reports in ten seconds

    The reporter wok adds all three files to URLhaus with the tag SilentNet.

  3. By 6 October 2026

    The files go offline

    URLhaus marks all three as offline. We do not know whether the owner, Supabase or someone else removed them.

  4. 6 October 2026

    Our check

    Our plain request gets 404 from Cloudflare.

How a .jar file like this reaches a player

Nobody gets infected by the storage address itself. A person downloads a .jar file through a link and runs it, usually as a Minecraft mod or a game client. We did not see how these three files were shared; the steps below are how Check Point Research described Java mod stealers on 18 June 2025.

Four steps: a link to a free mod, the jar copied into the mods folder, the game starts it, accounts leave the PC
How fake Minecraft mods steal accounts, after Check Point Research. The first step for these three files is not known.
  1. 1

    A link to a free mod or client

    Check Point found fake cheat tools and mods offered through GitHub repositories run by a paid distribution network. Other public listings name fake clients and optimizers. A file in a cloud storage bucket is easy to link from Discord, a forum or a video description.

  2. 2

    The player installs it

    The player copies the .jar file into the Minecraft mods folder, or double-clicks it if Java is installed. That is all the malware needs.

  3. 3

    The game starts it

    When Minecraft starts with the mod, Java runs its code with the same rights as the player. Check Point saw the first stage fetch a second Java stealer and then a third, .NET based stealer.

  4. 4

    The data is sent out

    The stealer packs up tokens, passwords and wallet files and sends them to its controller.

What aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files) can steal or download

What a Java mod stealer can take

We do not know exactly what these three files take. The list below is what Check Point found in the Java stealer chain it analysed in 2025, which is the closest published case.

Taken in the Check Point case

  • Minecraft session tokens
  • Discord tokens
  • Telegram data
  • Saved passwords in Chrome, Edge and Firefox
  • Crypto wallets
  • VPN settings
  • Steam log-ins
  • FileZilla log-ins
  • Clipboard contents
  • Screenshots
  • High

    Your Minecraft and Microsoft account

    A stolen session token lets someone use the account without the password until the session ends.

  • High

    Discord and messaging

    A Discord token lets the attacker post as you, often to spread the same fake mod to your friends. That is a common pattern; it is our reading for this case.

  • High

    Crypto

    Wallet files and clipboard data can lead to coins sent away, which cannot be reversed.

  • Medium

    Everything saved in the browser

    Saved passwords and cookies for email, shops and school or work accounts.

What you may notice

Stealers work in seconds and then go quiet. Most victims notice only when an account is misused.

None of these is certain; seeing none of them clears nothing.
SignWhat it can mean
Friends get messages from you with a download link you did not sendYour Discord or other account token was stolen
You are logged out of Minecraft, Discord or Steam, or see log-ins you did not makeSomeone is using a stolen session
A mod you added does nothing in the gameFake mods often have no real feature
A Defender alert for a .jar file or for java.exeMicrosoft blocked or found part of the chain; look in Protection history
Crypto missing from a walletWallet files or keys were taken

How to check the PC for aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files)

Who can meet this address

A .jar file runs wherever Java runs: Windows, Mac and Linux. Players who install mods from links are the people at risk.

Our reading of the file type and the published cases.
You areWhat it meansWhat to do
Someone who downloaded a mod, client or tool from a link with this addressYou may have one of the three filesIf you ran it, follow the steps on this page
A parent whose child plays Minecraft with modsThe child may have installed itCheck the mods folder and the child's accounts together
An admin who saw the address in a proxy or DNS logA device downloaded from this projectFind the device and check it
A Mac user who ran the fileJava runs on macOS too, and Check Point's first stages were JavaDelete the file, change passwords from another device, scan the Mac
An iPhone or Android userPhones do not run .jar filesNothing to remove
A Supabase customerYour own project is not affected by someone else's bucketNothing to do, unless your app lets strangers upload public files

Check your PC before you delete anything

Start with one question: did you download and run a .jar file from a link around 4 or 5 October 2026? If yes or not sure, do these checks. None of them deletes anything.

  1. 1

    Close the game and disconnect

    Quit Minecraft and its launcher, then turn off Wi-Fi or unplug the cable.

  2. 2

    Look in the mods folder

    Press Windows key + R, type %appdata%\.minecraft\mods and press Enter. Note any file you do not remember adding or that came from a link. Other launchers keep mods in their own instance folders.

  3. 3

    Check Downloads

    Look for .jar files with long number names or names of clients and optimizers.

  4. 4

    Read Protection history

    Open Windows Security > Virus & threat protection > Protection history and look for detections of .jar files or java.exe.

  5. 5

    Look at Startup apps

    Open Settings > Apps > Startup and note anything you do not recognise.

Windows Security Protection history listing recent detections
Windows 11 24H2, Windows Security > Protection history: look for a .jar or Java detection and its date.

How to remove aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files)

How to remove aqclqkcfjwbgknkwnvmm.supabase.co

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like aqclqkcfjwbgknkwnvmm.supabase.co add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after aqclqkcfjwbgknkwnvmm.supabase.co, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of aqclqkcfjwbgknkwnvmm.supabase.co that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Aqclqkcfjwbgknkwnvmm.supabase.co can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The Windows plan below is for Windows PCs. A .jar file can also run on a Mac with Java installed.

Your deviceWhat we knowWhat to do
MacJava runs on macOS and Minecraft mods are the same files thereDelete the mod, change passwords from another device, and remove anything you do not know from System Settings > General > Login Items
iPhone or iPadCannot run .jar filesNothing to remove; change passwords used on an infected computer
AndroidOrdinary Android does not run .jar desktop filesNothing to remove for this threat

After removal: passwords, accounts and prevention

After a clean PC: take your accounts back

Deleting the mod does not undo what it sent. Secure the accounts from another device first, starting with the ones a stealer is built to take.

Five steps in order: disconnect, secure accounts from another device, delete the mod, run an offline scan, reset if unsure
The order of actions if you ran one of these files. Based on Microsoft, Check Point and FTC advice; not tested on an infected PC.
  1. 1

    Microsoft account first

    From a phone or another computer, change the Microsoft account password used for Minecraft and sign out of all sessions in the account's security settings.

  2. 2

    Discord, email, Steam and the rest

    Change the passwords, log out of all devices and turn on two step sign in, as the FTC advises. A new Discord password also resets the stolen token.

  3. 3

    Move crypto

    If you had a wallet on the PC, move funds to a new wallet created on a clean device.

  4. 4

    Delete the mod and scan

    Remove the file from the mods folder and Downloads. Then run Windows Security > Virus & threat protection > Scan options > Microsoft Defender Antivirus (offline scan).

  5. 5

    Reset if unsure

    Check Point saw later stages that were not Java. If you are not sure all of it is gone, use Settings > System > Recovery > Reset this PC and reinstall the game from the official launcher.

  6. 6

    Warn your friends

    Tell the people you share mods with not to open the same link.

How to report the files

The files are offline already, but the same project could serve new ones.

  1. 1

    Report to Supabase

    Supabase hosts the project, so it can close it. Report the full project address through the contact options on supabase.com.

  2. 2

    Report to the place you found the link

    Report the post, video, repository or Discord message that pointed to the file, so others do not download it.

  3. 3

    Report account theft

    Use the recovery and hacked-account pages of Microsoft, Discord and Steam if you lost access.

How to keep fake mods off your PC

Check Point's main advice is simple: get mods only from legitimate sources.

Do

  • Download mods from the large mod sites and the authors' own pages, not from file links in chats or comments.
  • Keep a separate Minecraft profile for testing new mods, and back up worlds.
  • Use two step sign in on Microsoft, Discord, Steam and email.
  • Keep Windows and Microsoft Defender updated.

Don't

  • Do not run cheat clients, cracked launchers or optimizers sent as a .jar link.
  • Do not trust a link because a friend posted it; their account may be stolen.
  • Do not keep crypto wallets on the PC you use for modded games.
  • Do not change passwords on the PC you suspect.

Questions about aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files)

What is aqclqkcfjwbgknkwnvmm.supabase.co?

It is the address of one customer project on Supabase, a company that rents out databases and file storage. On 5 October 2026 URLhaus listed three .jar files in a public folder of that project, all tagged SilentNet.

Supabase is a legitimate service; the files belong to whoever made this project. We did not open the files, so their content is not confirmed by us.

Is this Supabase address safe?

The three reported files were marked offline on 6 October 2026, and our plain request got a 404 answer. That does not clear the project: whoever made it could upload new files.

Do not download .jar files from links to this address. Supabase itself, and other projects on supabase.co, are not affected by this report.

What is SilentNet?

It is the family name URLhaus gave these files. Public sandbox listings that appear in searches describe SilentNet as a Minecraft Fabric mod that steals session tokens and crypto wallet data.

We could not open those listings, so we treat the description as unconfirmed. Check Point's 2025 report on Java mod stealers shows what this kind of file can take.

I installed a mod from a link. Am I infected?

If the file came from this address and you ran it or started Minecraft with it, assume yes. Close the game, disconnect, and from another device change your Microsoft, Discord, email and Steam passwords and sign out of all sessions. Then delete the mod, run a Microsoft Defender Offline scan and reset Windows if you are not sure.

Can a .jar file infect a Mac?

Yes, if Java is installed. A .jar file is Java code, and Java runs on Windows, macOS and Linux. Minecraft mods are the same files on every system.

If you ran one of these files on a Mac, delete it, change passwords from another device and check Login Items in System Settings. Phones do not run these files.

Why do attackers use Supabase?

Free and cheap cloud storage gives a clean looking address on a known domain, which filters trust more than a new domain.

Supabase's documentation says a public bucket lets anyone with the file address download it. Researchers have also found malware that stores stolen data in Supabase databases. Supabase can close a project once it is reported.

How do I remove a fake Minecraft mod?

Delete the .jar file from the mods folder, which on Windows is in %appdata%\.minecraft\mods, and from Downloads. That removes only the first stage. Check Point saw these mods fetch more stealers, so run a Microsoft Defender Offline scan and check Startup apps too, and secure your accounts from another device first.

My friend sent me the link. Are they the attacker?

Probably not. Stealers often take Discord tokens and post the same link from the victim's account to their friends. Tell your friend by another way, such as a call or a text, that their account may be stolen, so they can change the password and sign out of all sessions.

Where should I get Minecraft mods?

Check Point advises getting mods only from legitimate sources. That means the large mod sites and the authors' own pages, not file links in chats, comments or video descriptions.

A mod that promises cheats, free capes or a faster client from an unknown link is the usual bait. Test new mods in a separate profile.

Will Fortect remove aqclqkcfjwbgknkwnvmm.supabase.co?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For aqclqkcfjwbgknkwnvmm.supabase.co, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: aqclqkcfjwbgknkwnvmm.supabase.co (SilentNet .jar files)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year