Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.
McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories.
Notably, one of the sites has been built using Lovable, an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites.
Weedhack was first documented by the cybersecurity company back in June 2026, detailing its use of SEO poisoning and YouTube to redirect traffic to the bogus domains. The attack triggers a multi-stage sequence that culminates in the deployment of JAR payloads that can collect system information, set up Microsoft Defender exclusions, and steal sensitive data from the compromised host.
“Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware,” McAfee Labs researcher Aayush Tyagi said.
Some of the fake domains distributing the malware are listed below –
- glazed-client[.]com, which replicates glazedclient[.]com, a free and open-source Minecraft add-on of the same name
- radium-client[.]com, which replicates radiumclient[.]com, a paid Minecraft client
- seedcrackerx.github[.]io, which replicates seedcrackerx[.]com, a Minecraft seed cracking software
- cheatlib[.]xyz, which claims to be a “modern Minecraft mod library” with more than 1.6 million downloads
- meteorclients[.]com, which replicates meteorclient[.]com
- 22qq-client[.]com, which impersonates a Minecraft mod of the same name for Crystal PvP servers
- kryptonclientcrack.lovable[.]app, which replicates kryptonclient[.]org, a paid Minecraft tool for DonutSMP server
- nova-client[.]com, which impersonates an open-source Minecraft client
- xenoclient[.]lol and xenonclient[.]com, which impersonate Xenon client
It’s worth noting that both the websites for Xenon Client and Nova Client feature at the top of search results across various search engines like Google, Microsoft Bing, Brave Search, and DuckDuckGo, allowing unsuspecting users to download Weedhack-laced clients.
“The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results,” McAfee Labs said.
Besides bogus domains, file hosting services and GitHub repositories have been observed spreading Weedhack, with links to these websites distributed via Discord, Reddit, and other communication channels. Another propagation channel involves hosting the JAR files on Planet Minecart and EndMods, both of which are legitimate destinations for Minecraft tools and enhancements.
To counter the threat, it’s advised to keep devices up-to-date, stick to trusted sources, scan files before opening them, and exercise caution when any mod or cheat prompts to disable security protections before installing it.
This is not the first time SEO poisoning campaigns for popular tools are being used to drop malware. In June 2026, Check Point flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework.
The post “Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning” appeared first on The Hacker News
Source:The Hacker News – [email protected] (The Hacker News)
