Vendor
Supabase
- First Reported
- May 11, 2026
- Latest Reported
- Aug 19, 2026
Reported Context (2)
- impersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases, private keys, or other Socket Links 77 Firefox Extensions to Crypto Wallet and Credential Theft
- These trojanized payloads established primary C2 channels through SaaS platforms ClickHouse and Supabase, with secondary backup channels capable of leveraging Ably, Dropbox, direct HTTP, or GitHub Issues. EtherRAT and TukTuk C2 Lead to The Gentlemen Ransomware Deployment
CVE (1)
Malware (3)
People (3)
MITRE ATT&CK (30)
Vendors (7)
Products (17)
Tools (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.