WeedHack Malware Targets Minecraft Players Through Fake Download Sites

Elayne Johnson  - VPNs Expert
Last updated: August 25, 2026
Human Written
Share
WeedHack Malware Targets Minecraft Players Through Fake Download Sites
Radar Rundown
  • McAfee blocked more than 6,300 attempts to reach sites that still spread WeedHack malware to Minecraft players.

  • Attackers copy real Minecraft clients, then use search results, Discord, GitHub and file hosts to push infected files.

  • One fake site used Lovable, an AI website builder, showing how easily attackers can create polished scam pages.

Fresh WeedHack malware attacks are now targeting Minecraft players. As McAfee Labs reported, many fake client sites still deliver this malware despite the disabling of the malware’s original C2 server.

Attackers take real Minecraft project pages, use SEO techniques and create fake download pages. They use such sites that people trust, such as Discord, MediaFire, Github, and others.

According to McAfee, they’ve blocked over 6,300 visits to malicious sites in the last month. However, the campaign tactics seem to have changed and are still very much active.

Fake sites copy real minecraft projects

The attackers build pages that closely match genuine Minecraft projects. McAfee found copied logos, feature lists, FAQs, installation guides and developer credits. Some fake sites also link to real GitHub projects. That detail can make a scam page seem genuine at first glance.

McAfee identified fake sites for Glazed Client, Radium Client, SeedCrackerX, Meteor Client, Nova Client and Xenon Client.

In one case, the fake Glazed Client site offered three downloads. McAfee found WeedHack in all three files. The fake Radium Client site used another common trick. The real Glazed Client site goes for $9.99 per month, while the fake site is totally free of charge. The downloaded JAR file carried WeedHack.

That free offer can be enough to convince a player to ignore other warning signs.

Search results put Malware in front of players

The campaign also relies on SEO poisoning. The attackers’ goal is to get search engines to push their fake sites to the top of search results for popular names players are already familiar with.

The researchers at McAfee noted fake sites promoting Nova Client and Xenon Client to be ranked highly in the search results of Google, Bing, Brave Search and DuckDuckGo.

For Nova Client, the legitimate client comes from GitHub and Modrinth. Attackers created a spoofed site and worked to outrank those sources. This tactic matters because users often trust the first few search results. A high ranking does not prove that a download is safe.

McAfee first documented WeedHack in June. Its research found 3,820 unique malicious JAR files and more than 240 URLs tied to the campaign. The campaign had operated since January 2026 and used YouTube videos and SEO poisoning to attract victims. McAfee also reported that the wider campaign had infected more than 116,464 gamers.

Trusted platforms are also part of the campaign

The attackers don’t depend on fake sites alone. According to McAfee, 49.6% of the harmful URLs that it examined were Discord links. MediaFire accounted for 23.4%, GitHub for 8.2% and Dropbox for 4.6%.

Cybercriminals were also sending links via Discord, Reddit, and other such forums. Researchers found malicious JAR files on Minecraft community sites, including Planet Minecraft and EndMods. This tactic adds another layer of trust around the downloads.

A fake site may also point visitors to a genuine GitHub repository. The real link can distract from the infected download sitting next to it.

AI tools are capable of speeding up fake site creation

McAfee also founded a WeedHack site built with Lovable, an AI-powered website creation platform. The site, kryptonclientcrack[.]lovable[.]app, copied Krypton Client. The legitimate tool targets players on the DonutSMP Minecraft server.

The discovery does not mean Lovable itself caused the malware campaign. Rather, it means the opposite, attackers can easily use web development tools to create legit-looking pages without breaking any sweat. The researchers at McAfee point out that AI technologies could allow scammers to create convincing clones much more quickly.

Nextcloud, a European cloud provider, experienced a similar incident where its official website was compromised and visitors were redirected to a suspicious Cloudbox site. The company initially downplayed the breach as ‘infrastructure problems,’ though a WordPress vulnerability (WP2Shell) was later suspected.

WeedHack steals more than minecraft data

WeedHack is not simply a bad Minecraft mod. McAfee’s earlier research found a multi-stage attack. The first JAR file can download more components, collect system details and add Microsoft Defender exclusions.

The malware can also steal Minecraft session IDs, browser cookies and passwords. It can target Discord, Steam and Telegram credentials. It can also steal data from browser-based crypto wallets and desktop wallets.

The premium version offers users remote access features, like webcam access, keylogging, screensharing, and transfer of files. McAfee also described WeedHack as a malware-as-a-service operation. The dashboard shows customers can build version 1.21.0 to 1.21.11 of Minecraft payload and then inject it into legitimate mods.

How to players can protect themselves 

Minecraft players should obtain mods from developers’ websites or official modding websites like Modrinth. They should check the domain name before opening a download.

They should also scan files before running them. Most importantly, no mod, cheat or client should require users to disable Microsoft Defender or other security tools.

The WeedHack campaign shows why search results need a second look. Attackers can copy a real project’s design, link to genuine resources and still hide malware behind the download button. For Minecraft players, checking the source can take a few extra seconds. That small step could prevent a much bigger problem.

Share this article

About the Author

Elayne is a passionate tech blogger and digital security enthusiast. She has extraordinary writing and communication skills, assisting her in performing her tasks very well. She keeps educating herself about new trends in cybersecurity and educates others about it. Elayne loves learning about tech, VPNs, security, and online anonymity. In her free time, she enjoys trying new tech gadgets, watching movies, and using social media.

More from Elayne Johnson

Comments

No comments.