Fake Minecraft client sites are still topping search results and handing gamers the WeedHack infostealer months after researchers disrupted its command-and-control setup.
McAfee Labs reports that more than 6,300 attempts to reach the malicious pages were blocked in the past month alone. The lookalike sites clone real tools such as Xenon Client, Nova Client, Radium Client, and Meteor Client, complete with feature lists, FAQs, install guides, and links to genuine GitHub repositories. One fake site was built with the AI-powered Lovable website builder, a sign that launching convincing lures now takes near-zero skill.
WeedHack first surfaced in June 2026 as a malware-as-a-service operation that had logged 116,464 infected systems, adding 2,000 to 3,000 victims daily. It steals cookies, passwords, browser data, and crypto wallets, and uses the EtherHiding trick to pull fresh server addresses from the Ethereum blockchain. After McAfee published its initial report, the C2 server went dark, but the distribution machine kept running.
The campaign leans on SEO poisoning: for queries like Xenon Client, the first two Google results were fake download pages. Nearly half of the malicious links spread through Discord (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%).
McAfee urges gamers to download mods only from official developer repositories or trusted platforms such as Modrinth and CurseForge, and to treat any tool that asks them to disable antivirus as malware.
