Cybersecurity researchers have uncovered an ongoing campaign distributing the Weedhack malware to gamers through fake Minecraft clients and SEO poisoning. McAfee Labs reported detecting and blocking over 6,300 attempts to access malicious sites, with lookalike gaming websites mimicking legitimate projects, including branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories. One such site was built using Lovable, an AI-powered website builder, highlighting how accessible tools lower the barrier for creating convincing malicious sites.
Weedhack was first documented by McAfee Labs in June 2026, detailing its use of SEO poisoning and YouTube to redirect traffic to bogus domains. The attack triggers a multi-stage sequence that culminates in the deployment of JAR payloads capable of collecting system information, setting up Microsoft Defender exclusions, and stealing sensitive data from compromised hosts. According to McAfee Labs researcher Aayush Tyagi, nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers leverage familiar platforms alongside fake websites.
Fake domains distributing Weedhack include glazed-client[.]com, radium-client[.]com, seedcrackerx.github[.]io, cheatlib[.]xyz, meteorclients[.]com, 22qq-client[.]com, kryptonclientcrack.lovable[.]app, nova-client[.]com, xenoclient[.]lol, and xenonclient[.]com. Notably, the spoofed Xenon Client and Nova Client websites rank at the top of search results on Google, Microsoft Bing, Brave Search, and DuckDuckGo, outranking official sources. The legitimate clients are hosted on GitHub and Modrinth, but attackers have used SEO poisoning to outrank them.
Beyond bogus domains, file hosting services and GitHub repositories have been observed spreading Weedhack, with links distributed via Discord, Reddit, and other channels. JAR files are also hosted on Planet Minecart and EndMods, legitimate destinations for Minecraft tools. To counter the threat, users are advised to keep devices updated, stick to trusted sources, scan files before opening, and be cautious when mods or cheats prompt to disable security protections. This campaign follows a similar June 2026 operation flagged by Check Point that impersonated open-source projects to deliver malware families like Remus Stealer, AnimateClipper, and SessionGate.
CVEs: CVE-2026-58231
Malware: Weedhack, Remus Stealer, AnimateClipper, SessionGate
Companies: McAfee Labs, Check Point, Lovable
Products: Microsoft Defender
Original source: thehackernews.com