Cybersecurity researchers have uncovered multiple fraudulent websites actively spreading a malware strain called Weedhack by posing as Minecraft clients. McAfee Labs reported detecting and stopping more than 6,300 attempts to reach malicious sites, according to a new analysis released in August 2026. The fake gaming websites replicate legitimate projects down to their branding, feature descriptions, FAQs, setup instructions, developer acknowledgments, and connections to authentic GitHub repositories.

The attackers relied heavily on familiar platforms to spread their malware, with nearly half of all malicious URLs pointing to Discord links at 49.6%, followed by MediaFire at 23.4% and GitHub at 8.2%, the report states. At least eleven fake domains have been identified distributing the malware, including sites impersonating Glazed Client, Radium Client, Meteor Client, Krypton Client, Nova Client, and Xenon Client. One fraudulent site was constructed using Lovable, an AI-powered website creation tool, demonstrating how accessible technology can reduce the effort needed to build convincing malicious platforms. The attack unfolds through multiple stages, ultimately deploying JAR payloads that gather system details, configure Microsoft Defender exclusions, and extract sensitive information from infected machines.

Both the Nova Client and Xenon Client impostor websites rank at the top of search results across Google, Microsoft Bing, Brave Search, and DuckDuckGo, enabling unsuspecting users to download compromised clients, McAfee Labs noted. "The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results," the researchers explained. According to McAfee Labs researcher Aayush Tyagi, the distribution channels extend beyond fake domains to include file hosting services and GitHub repositories, with links circulated through Discord, Reddit, and other communication platforms. Attackers have also uploaded JAR files to Planet Minecart and EndMods, both legitimate destinations for Minecraft tools and modifications.

The report traces Weedhack's tactics back to June 2026, when McAfee Labs first documented the malware's use of SEO poisoning and YouTube to funnel traffic toward bogus domains. The success of these fraudulent sites stems from their ability to outperform official sources in search rankings, intercepting users who search for popular Minecraft clients and mods. This attack pattern mirrors a broader trend identified in June 2026 by Check Point, which flagged a large-scale operation impersonating open-source and freeware projects to direct users through a Traffic Distribution System and deliver malware families including Remus Stealer, AnimateClipper, and the SessionGate framework.

To defend against the threat, the report recommends keeping devices current with updates, downloading only from trusted sources, scanning files prior to opening them, and treating any mod or cheat that requests disabling security protections before installation as a red flag. The concentration of malicious URLs on Discord, MediaFire, and GitHub highlights the need for heightened scrutiny even when links appear on familiar platforms. Organizations and individual gamers alike should recognize that the barrier to launching convincing phishing operations has dropped considerably, making routine verification of website authenticity a necessary precaution before downloading any gaming modification. As search engines continue to surface fraudulent sites above legitimate repositories, users who rely solely on top search results face escalating risk of infection.