Security researchers at McAfee Labs warned this week that a Windows malware family called WeedHack is still spreading through fake Minecraft client and mod downloads, using rigged Google search results to trick players — often kids and teens — into installing it. The malware can steal passwords, files, and crypto wallet data, and in its paid version it even lets attackers watch your webcam and take remote control of your PC. This is a national report, not a local incident, but any York-area household with a gamer in the family is a target.
What WeedHack Is and What It Does
WeedHack is a Windows malware service that steals accounts, passwords, files, and cryptocurrency wallet data from gamers who are directed to fake Minecraft client, mod, and cheat websites. It's sold to cybercriminals in free and paid tiers, with the more expensive version adding keylogging, webcam access, remote screen control, and command-line access to an infected computer.
McAfee Labs describes it as a Malware-as-a-Service (MaaS) operation that lets attackers remotely access and manipulate victims' screens, webcams, and file systems through a dashboard hosted on the clear net, making it accessible to anyone with a Discord account and an internet connection. In plain English: once it's on a Windows PC, whoever paid for it can watch, record, and rummage through everything on that machine.
If a family PC has been acting strange after a Minecraft mod install — unexpected pop-ups, browser hijacks, missing files, or a webcam light coming on by itself — those are classic signs it's time to remove a malware infection before the damage spreads to saved passwords and banking sessions.
How the Scam Reaches Your PC
The core trick is SEO poisoning — attackers rank fake download sites above the real ones in Google. According to McAfee Labs, the legitimate clients are hosted on GitHub and Modrinth, but attackers have created spoofed websites and used SEO poisoning to outrank the official sources in search results. In one test, McAfee found that the first two Google results for Xenon Client led to websites distributing WeedHack.
Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers use familiar platforms alongside fake websites to distribute malware. Attackers also create convincing YouTube videos reviewing or demonstrating Minecraft clients and mods, some with voiceover narration, that link to malicious downloads in the description and comments — one video had over 7,500 views before being flagged.
Minecraft clients and mods being specifically impersonated include Meteor Client, Radium Client, Wurst Client, LiquidBounce, Impact Client, and Future Client, among others.
Scale of the Campaign
This isn't a small operation. McAfee first documented WeedHack in June as a malware-as-a-service operation active since January 2026, identifying more than 3,820 malicious JAR files and over 240 distribution URLs, with the campaign dashboard recording 116,464 hits and roughly 2,000 to 3,000 added daily.
Although WeedHack's original command server and customer dashboard later went offline, a new investigation found that other websites and download links continued spreading the malware, and McAfee WebAdvisor blocked more than 6,300 attempted visits to associated sites during the past month. In other words, the takedown didn't stick — the campaign has simply shifted hosting.
How to Protect Your PC
McAfee's advice is straightforward. Keep devices up to date, stick to trusted sources, scan files before opening them, and be cautious when any mod or cheat prompts you to disable security protections before installing it.
A few practical rules for parents and gamers:
- Only download Minecraft mods and clients from the official project pages on Modrinth, CurseForge, or the developer's verified GitHub — never from a Google ad or the top organic result without checking the URL character-by-character. - Never turn off Windows Defender, SmartScreen, or your antivirus because a "mod installer" told you to. Legitimate mods don't require that. - Treat Discord and MediaFire links posted in random servers as untrusted by default. - If a PC is already infected, change every saved password from a different, clean device — not from the compromised machine.
If the infection has caused Windows to crash, boot loop, or lock up, you may need more than a virus scan — a technician may need to do a full desktop repair and cleanup, and if personal files or Minecraft worlds got encrypted or wiped, professional file recovery may be the only way to get them back.
What This Means for York, PA
York County has plenty of households with kids playing Minecraft on the family Windows PC, and this is exactly the kind of infection we see walk through the door — a parent brings in a slow, ad-riddled computer after a child installed a "free" cheat client. If your PC is showing signs of infection, York Computer Repair can clean it up at our shop at 2069 Carlisle Rd — call 717-739-9675 during weekday hours before the malware harvests saved passwords or banking info.