HackMyIP
← Back to News
2026-08-24 The Hacker News

Weedhack Malware Targets Minecraft Players via Fake Clients and SEO Poisoning

MalwareThreat IntelPhishing

Cybersecurity researchers at McAfee Labs have uncovered an ongoing campaign in which the Weedhack malware family is being distributed to gamers through fraudulent Minecraft client websites and search engine optimization (SEO) poisoning techniques. Since its initial documentation in June 2025, the malware operation has scaled significantly, with McAfee detecting and blocking more than 6,300 attempts to access malicious domains hosting the payloads. The fraudulent sites are carefully crafted to mimic legitimate open-source projects, complete with accurate branding, feature lists, FAQs, installation guides, developer credits, and direct links to authentic GitHub repositories. One notable case involved a malicious site built using Lovable, an AI-powered website builder, underscoring how accessible development tools are accelerating the deployment of convincing phishing infrastructure.

Weedhack's attack chain is multi-stage and culminates in the execution of JAR payloads capable of harvesting system information, configuring Microsoft Defender exclusions to evade detection, and exfiltrating sensitive data from compromised hosts. McAfee researcher Aayush Tyagi noted that nearly half of the malicious URLs identified (49.6%) were Discord links, followed by MediaFire at 23.4% and GitHub at 8.2%, demonstrating how attackers weaponize familiar platforms alongside lookalike websites. Victims searching for clients such as Xenon Client or Nova Client are particularly at risk, as the spoofed domains frequently outrank legitimate GitHub and Modrinth pages across Google, Microsoft Bing, Brave Search, and DuckDuckGo. Researchers and end users can investigate suspicious domains using a WHOIS lookup to verify registration details and ownership history before downloading any software.

The identified malicious domains include glazed-client[.]com, radium-client[.]com, seedcrackerx.github[.]io, cheatlib[.]xyz, meteorclients[.]com, 22qq-client[.]com, kryptonclientcrack.lovable[.]app, nova-client[.]com, xenoclient[.]lol, and xenonclient[.]com, each impersonating well-known Minecraft mods, clients, or utilities. Beyond fake websites, Weedhack is also propagated through file hosting services and public GitHub repositories, with malicious links spread across Discord, Reddit, and other communication channels. Gamers who suspect their credentials or system data may have been exposed should run a password checker to evaluate the strength and breach status of their credentials, and consider performing a browser fingerprint test to assess what identifiable information their system may be leaking. McAfee recommends that users always verify the source URL against official project repositories and avoid downloading Minecraft clients or mods from unverified search results.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →