If you're a Minecraft player looking for cool new clients or mods, watch out. Cybersecurity researchers found that several websites are still pushing a malware called Weedhack. They pretend to offer legit Minecraft clients, but they're actually out to steal your data.
McAfee Labs said they blocked more than 6,300 attempts to access these malicious sites. The fake sites look convincing. They copy branding, feature lists, FAQs, and installation guides. Some even use links to actual repositories on GitHub to appear legitimate.
The site had been built using Lovable, an AI website generator. This proves how simple it is now to build fake websites that are quite convincing.
Are you a Minecraft player? Well, this has everything to do with you. Here is an explanation of what is going on.
Quick Summary
|
What |
Details |
|
Malware |
Weedhack |
|
Target |
Gamers looking for Minecraft clients |
|
Tactics |
SEO poisoning, fake websites |
|
Platforms |
Discord, MediaFire, GitHub |
|
Detected |
6,300+ access attempts |
|
First Found |
June 2026 |
How the Scam Works
Fake Websites
Attackers build copycat sites that look exactly like real Minecraft client projects. Branding, features, and even FAQ's are all stolen by them. It is made to seem so real that most people would not question it at all.
SEO Poisoning
SEO tactics are used by the scammers in order to have their fake website rank above the real one. Therefore, when searching for a Minecraft client, the fake website ranks above the real one.
Multi-Stage Attack
Once you download the fake client, a chain of events starts. The malware drops JAR payloads that steal system info, disable Microsoft Defender, and grab sensitive data from your computer.
Fake Domains to Watch Out For
Here are some of the fake domains McAfee found:
|
Fake Domain |
What It Copies |
|
glazed-client[.]com |
glazedclient[.]com |
|
radium-client[.]com |
radiumclient[.]com |
|
seedcrackerx.github[.]io |
seedcrackerx[.]com |
|
cheatlib[.]xyz |
Claims to be a "modern Minecraft mod library" |
|
meteorclients[.]com |
meteorclient[.]com |
|
22qq-client[.]com |
A mod for Crystal PvP servers |
|
kryptonclientcrack.lovable[.]app |
kryptonclient[.]org |
|
nova-client[.]com |
An open-source Minecraft client |
|
xenoclient[.]lol |
Xenon client |
|
xenonclient[.]com |
Xenon client |
Where the Malware Is Shared
McAfee found that attackers use familiar platforms to spread the malware:
|
Platform |
Percentage |
|
Discord |
49.6% |
|
MediaFire |
23.4% |
|
GitHub |
8.2% |
They also use Reddit, Planet Minecart, and EndMods.
What the Malware Does
Once installed, Weedhack can:
- Collect system information
- Disable Microsoft Defender
- Steal sensitive data from your computer
How to Stay Safe
1. Download Only from Authentic Sources
Go always to the developer's official site. Do not believe everything you see in search results.
2. Look at the URL
Fake websites usually contain tiny mistakes. Be careful!
3. Scan Files Before Opening
Run any downloaded file through your security software first.
4. Don’t Take Any Threats to Your Security Seriously
Any modification or cheat asking you to turn off your antivirus is a major warning sign.
5. Keep Everything Updated
Update your operating system and security software regularly.
The Bigger Picture
SEO poisoning isn't new. In June 2026, Check Point also identified yet another similar campaign where the attackers leveraged open-source impostors to deliver malware, including Remus Stealer and AnimateClipper.
Bottom Line
Weedhack is using fake clients to hack into the Minecraft gaming community. They have been using techniques in SEO to position themselves high on search results.
What You Need to Know:
|
Key Point |
Detail |
|
Malware |
Weedhack |
|
Target |
Minecraft gamers |
|
Tactic |
SEO poisoning + fake websites |
|
Distribution |
Discord, MediaFire, GitHub |
|
Detected |
6,300+ access attempts |
What Do You Have To Do:
- Access from legitimate sources
- Verify website addresses
- Scan downloaded documents
- Update anti-virus software
FAQ Section
What is Weedhack malware?
It's a malware family that pretends to be Minecraft clients.It steals information from the system and other sensitive data.
How is it done?
They make fake websites for Minecraft and manipulate their SEO ranking. The user downloads the malware.
Where is malware shared by attackers?
They are shared on Discord, MediaFire, GitHub, Reddit, Planet Minecart, and EndMods.
How can I protect myself?
Only download from official sources. Check URLs. Scan files. Keep security software updated.
Has such a thing ever happened before?
Yes, a case of SEO poisoning was revealed in June 2026 by Check Point.