Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.
McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories.
Notably, one of the sites has been built using Lovable, an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites.
Weedhack was first documented by the cybersecurity company back in June 2026, detailing its use of SEO poisoning and YouTube to redirect traffic to the bogus domains. The attack triggers a multi-stage sequence that culminates in the deployment of JAR payloads that can collect system information, set up Microsoft Defender exclusions, and steal sensitive data from the compromised host.
"Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware," McAfee Labs researcher Aayush Tyagi said.
Some of the fake domains distributing the malware are listed below -
- glazed-client[.]com, which replicates glazedclient[.]com, a free and open-source Minecraft add-on of the same name
- radium-client[.]com, which replicates radiumclient[.]com, a paid Minecraft client
- seedcrackerx.github[.]io, which replicates seedcrackerx[.]com, a Minecraft seed cracking software
- cheatlib[.]xyz, which claims to be a "modern Minecraft mod library" with more than 1.6 million downloads
- meteorclients[.]com, which replicates meteorclient[.]com
- 22qq-client[.]com, which impersonates a Minecraft mod of the same name for Crystal PvP servers
- kryptonclientcrack.lovable[.]app, which replicates kryptonclient[.]org, a paid Minecraft tool for DonutSMP server
- nova-client[.]com, which impersonates an open-source Minecraft client
- xenoclient[.]lol and xenonclient[.]com, which impersonate Xenon client
It's worth noting that both the websites for Xenon Client and Nova Client feature at the top of search results across various search engines like Google, Microsoft Bing, Brave Search, and DuckDuckGo, allowing unsuspecting users to download Weedhack-laced clients.
"The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results," McAfee Labs said.
Besides bogus domains, file hosting services and GitHub repositories have been observed spreading Weedhack, with links to these websites distributed via Discord, Reddit, and other communication channels. Another propagation channel involves hosting the JAR files on Planet Minecart and EndMods, both of which are legitimate destinations for Minecraft tools and enhancements.
To counter the threat, it's advised to keep devices up-to-date, stick to trusted sources, scan files before opening them, and exercise caution when any mod or cheat prompts to disable security protections before installing it.
This is not the first time SEO poisoning campaigns for popular tools are being used to drop malware. In June 2026, Check Point flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework.
Facts Only
McAfee Labs blocked over 6,300 attempts to access sites distributing Weedhack malware.
Weedhack targets gamers by masquerading as Minecraft clients.
Malware is delivered via JAR payloads that collect system information, steal sensitive data, and create Microsoft Defender exclusions.
Distribution channels include spoofed websites, Discord (49.6%), MediaFire (23.4%), and GitHub (8.2%).
Specific spoofed domains include glazed-client[.]com, radium-client[.]com, and meteorclients[.]com.
Some malicious sites use the AI-powered builder Lovable.
SEO poisoning is used to rank fake sites above official sources on Google, Bing, Brave, and DuckDuckGo.
Legitimate platforms such as Planet Minecart and EndMods have hosted the malicious JAR files.
Weedhack was first documented in June 2026.
Check Point identified a separate operation in June 2026 delivering Remus Stealer, AnimateClipper, and SessionGate.
Executive Summary
Cybersecurity threats targeting the Minecraft community have intensified through the distribution of the Weedhack malware family. Attackers employ a sophisticated multi-stage approach, utilizing SEO poisoning to ensure spoofed websites outrank legitimate projects in major search engine results. These fraudulent sites often meticulously mimic the branding, documentation, and credits of genuine clients to deceive users into downloading malicious JAR payloads.
The campaign leverages a hybrid distribution network, combining dedicated fake domains with trusted third-party platforms like Discord, GitHub, and MediaFire. Notably, the adoption of AI-powered website builders has reduced the technical barrier for creating convincing landing pages. Once installed, the malware targets sensitive host data and actively disables security software. While these attacks are widespread, they follow a broader pattern of impersonating open-source and freeware projects to funnel users toward diverse malware families.
Full Take
The strongest version of this narrative is a cautionary alert: the democratization of web creation via AI and the manipulation of search algorithms have made "visual trust" an obsolete security metric. When a site looks identical to a legitimate project and ranks first on Google, the traditional advice to "check the URL" is no longer sufficient for the average user.
This situation reveals a systemic vulnerability in how we perceive digital authority. The load-bearing assumption is that search engine rankings and professional aesthetics correlate with legitimacy. By weaponizing SEO and AI builders, attackers are not just deploying malware; they are exploiting the cognitive shortcuts users take to verify truth. This is a classic "Trust Transition" pattern where the bridge between a user's intent (finding a mod) and the destination is hijacked.
The root cause is the inherent tension between open-source accessibility and security. The very nature of the modding community—relying on community-hosted JAR files and third-party repositories—creates a massive attack surface. The second-order consequence is a potential "trust collapse" where users may stop trusting legitimate open-source distributions entirely, driving them toward closed, proprietary ecosystems that promise safety but sacrifice transparency.
Patterns detected: none
If this were a coordinated influence campaign, the playbook would involve exaggerating the "AI threat" to create a panic that justifies the purchase of specific, expensive security suites, framing AI not as a tool for efficiency but as an existential weapon. The current content does not match this pattern; it provides specific technical indicators and general hygiene advice.
Bridge Questions:
1. If SEO can be so easily poisoned, what new standards for "Proof of Origin" must the open-source community adopt?
2. How does the shift toward AI-generated content change the way we teach digital literacy to younger generations?
3. At what point does the convenience of third-party mod platforms outweigh the systemic security risks they introduce?
