How Weedhack reaches gamers
McAfee Labs' analysis shows Weedhack is distributed through a blend of SEO poisoning, social platforms, file hosts and direct links on developer-style sites. The campaign uses search-engine manipulation and YouTube redirection to steer users toward spoofed download pages; links are then propagated over Discord, Reddit and other communication channels. McAfee recorded and blocked more than 6,300 attempts to access malicious sites tied to this activity.
Fake Minecraft sites being used to deliver Weedhack
Researchers found lookalike gaming websites constructed to mimic legitimate Minecraft projects, complete with branding, feature lists, FAQs, installation guides and links that point to genuine GitHub repositories. Some of the domains observed by McAfee Labs include:
- glazed-client[.]com (replicates glazedclient[.]com)
- radium-client[.]com (replicates radiumclient[.]com)
- seedcrackerx.github[.]io (replicates seedcrackerx[.]com)
- cheatlib[.]xyz
- meteorclients[.]com (replicates meteorclient[.]com)
- 22qq-client[.]com
- kryptonclientcrack.lovable[.]app (replicates kryptonclient[.]org)
- nova-client[.]com
- xenoclient[.]lol and xenonclient[.]com
McAfee Labs noted that the spoofed sites sometimes mirror legitimate project pages hosted on GitHub and Modrinth, and that attackers have leveraged familiar hosting and file-storage destinations — including Planet Minecart and EndMods — to place JAR files alongside genuine Minecraft tools.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWeedhack's technical behavior and staging
According to McAfee Labs, Weedhack follows a multi-stage infection chain that ultimately delivers JAR payloads. Those payloads are capable of collecting system information, configuring Microsoft Defender exclusions, and stealing sensitive data from compromised hosts. The malware family was first documented by McAfee Labs in June 2026, and continued monitoring has shown active distribution in the months since.
Search-engine poisoning, AI site builders, and hosting abuse
McAfee researchers observed that spoofed sites for at least two clients — Xenon Client and Nova Client — were appearing at the top of search results on Google, Microsoft Bing, Brave Search and DuckDuckGo, enabling unsuspecting users to download Weedhack-laced clients rather than the official releases. McAfee noted that attackers created spoofed websites and used SEO poisoning techniques to outrank the legitimate sources.
The report also highlighted a notable operational detail: one malicious site was built using Lovable, an AI-powered website builder, demonstrating how readily available tools can lower the barrier for launching convincing fraudulent pages. McAfee emphasized that, beyond fake domains, file hosting services and GitHub repositories have been used in distribution chains.
What this means for technologists, gamers, and open-source maintainers
- Technologists and security teams: prioritize detection of suspicious JAR behavior and Microsoft Defender exclusion changes; monitor referrals from social platforms and file hosts like MediaFire and Planet Minecart for anomalous downloads.
- Gamers and end users: follow McAfee Labs' guidance to keep devices up to date, stick to trusted download sources, scan files before opening them, and exercise caution when a mod or cheat prompts you to disable security protections.
- Open-source maintainers and project hosts: be aware that legitimate repositories on GitHub and Modrinth may be left behind in search results when attackers use spoofed web pages and SEO poisoning to outrank official project pages.
This campaign is consistent with earlier SEO poisoning operations: in June 2026, Check Point reported a large-scale impersonation effort that funneled users through Traffic Distribution Systems to deliver malware families including Remus Stealer, AnimateClipper and the SessionGate framework. McAfee's findings underscore that attackers are combining familiar platforms, legitimate hosting services and even AI website builders to broaden reach and increase plausibility for would-be victims.
For now, the practical defenses remain the same and the stakes are straightforward: users who rely on search results and third-party links for game clients may be diverted to malicious pages that deliver data-stealing JARs and attempt to neutralize endpoint protections. Vigilance over sources, routine scanning, and scrutiny of any request to disable security software are the immediate countermeasures recommended by McAfee Labs.




