WeedHack Malware Campaign Targets Minecraft Players Through Fake Mods and YouTube Videos
Security researchers are warning Minecraft players about WeedHack, a malware-as-a-service campaign that spreads through fake Minecraft mods, hacked clients, YouTube videos, and search-poisoned websites. McAfee Labs says the campaign has been active since January 2026 and has logged 116,464 hits, with roughly 2,000 to 3,000 new hits per day.
The campaign matters because it turns the normal search for Minecraft mods into a credential theft and remote access risk. According to the research report, WeedHack has used more than 3,820 malicious JAR files and over 240 distribution URLs to reach players looking for free clients, cheats, utilities, and mod downloads.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
WeedHack is not just a single malicious file. It works as a service platform for attackers, with a dashboard that lets customers build payloads, monitor infected systems, view stolen credentials, and follow tutorials on how to spread the malware.
How WeedHack Reaches Minecraft Players
The campaign uses two main distribution methods: YouTube promotion and SEO poisoning. Attackers post polished videos that appear to demonstrate Minecraft mods or clients, then place download links in descriptions, comments, or related pages. Some of these videos use voiceovers and clean editing to look more convincing.
SEO poisoning helps the fake pages appear when players search for popular Minecraft clients or mods. This tactic works especially well when a project has no clear official website, because a malicious page can look like the most trustworthy result to a young player or a casual user.
A separate McAfee security advisory says the campaign has also attracted younger would-be attackers. McAfee says some customers appeared to use the malware not only for account theft, but also to harass victims after gaining access to webcams or files.
What WeedHack Can Steal
Once a player runs the infected JAR file, WeedHack starts a multi-stage infection chain. The malware can collect system details, steal browser data, take screenshots, hijack Minecraft sessions, and deploy further tools for persistence and remote access.
| Area | Reported WeedHack capability |
|---|---|
| Browsers | Steals cookies and passwords from 36 browsers |
| Crypto wallets | Targets 56 browser-based wallets and 12 desktop wallets |
| Gaming and chat accounts | Targets Minecraft session IDs, Discord, Steam, and Telegram credentials |
| Remote access | Premium features can include screen access, webcam access, keylogging, and reverse shell execution |
| Persistence | Uses scripts and scheduled tasks to make removal harder |
McAfee says WeedHack also uses EtherHiding, a technique that retrieves the latest command-and-control domain from the Ethereum blockchain. The responses are RSA-signed before execution, which helps the operators protect their infrastructure from outside takeover attempts.

The malware has also appeared in public threat tracking. MalwareBazaar lists WeedHack-tagged samples with activity first seen in January 2026 and last seen in May 2026, giving defenders another place to track related files.
Why Minecraft Mods Are an Easy Target
Minecraft has a large modding scene, and many players are used to downloading JAR files from the web. That creates an opening for attackers who can make a fake page look like a normal mod site, especially when they copy names, logos, screenshots, or links to real communities.
The Fabric documentation warns that many websites claim to offer Minecraft mods but are actually malware sites. It recommends using known sources such as Modrinth and CurseForge, checking with others when a source looks unfamiliar, and avoiding suspicious download pages.
WeedHack takes advantage of the same habits. A player sees a video, finds a download link, ignores a warning, and runs a file that looks like a Minecraft tool. From there, the malware can start stealing accounts before the victim understands what happened.
What Players and Parents Should Do Now
Players should treat free Minecraft clients, cracked clients, cheat tools, and mod downloads from unknown websites as high risk. A page that asks users to disable antivirus protection, ignore browser warnings, or run a suspicious JAR file should be treated as unsafe.
- Download Minecraft mods only from known and trusted platforms or the developerโs verified page.
- Avoid links in YouTube descriptions, Discord messages, Reddit comments, and file-hosting pages unless the source can be confirmed.
- Do not disable antivirus protection to install a Minecraft mod or client.
- Scan suspicious downloads before opening them, but do not rely on scans as the only safety check.
- Change passwords immediately if a suspicious mod was opened on the device.
- Enable two-factor authentication on Microsoft, Discord, Steam, Telegram, and crypto wallet accounts where available.
Players can also compare any unfamiliar download page with trusted-source guidance before running a file. If a mod has no clear developer page, no reputable listing, and only appears through search ads, YouTube links, or random mirrors, it should be avoided.
Anyone who already ran a suspicious Minecraft JAR should disconnect from sensitive accounts, change passwords from a clean device, and run security checks. Microsoft says the Microsoft Safety Scanner can find and remove malware from Windows computers, although it does not replace real-time antivirus protection.
Why WeedHack Is Harder to Remove
WeedHack is designed to stay on a system after the first execution. Reports describe scripts that add Windows Defender exclusions and scheduled tasks that can restore removed components. This means a simple file deletion may not remove the full infection.

The campaignโs malware-as-a-service model also makes the threat more scalable. Attackers do not need advanced malware development skills. They can use a dashboard, select options, generate a payload, and follow ready-made distribution instructions.
The safety guidance also warns victims not to follow instructions from someone claiming to have hacked their computer. If a child or teenager receives threats involving stolen files, webcam footage, or account access, they should contact a trusted adult and report the incident instead of engaging with the attacker.
Current WeedHack Indicators
Security teams can use public indicators and malware samples to improve detection. The WeedHack tag on MalwareBazaar provides a sample-focused view of activity, while security vendors have published additional hashes, domains, file names, and detection names tied to the campaign.
| Indicator type | Examples reported in public research |
|---|---|
| Malicious file type | Java JAR files disguised as Minecraft mods or clients |
| Stage names | DonutDupe.jar, elevator.jar, SecurityManager.jar, component.jar |
| Windows payload names | Telemetry.exe, RuntimeBroker.exe, chromedriver.dll |
| Persistence scripts | Updater.vbs, elv.vbs, WinDefConfig.cmd |
| Detection names | Trojan:Win/Weedhack and Trojan:Script/Weedhack variants |
If a device shows signs of compromise, users should run a full antivirus scan, review startup items, check browser sessions, revoke suspicious logins, and reinstall affected launchers from clean sources. Windows users who need an additional manual check can download the latest scan tool before each scan so it uses current anti-malware definitions.
WeedHack shows how gaming communities remain a valuable target for credential thieves. Minecraft players often search for mods outside official marketplaces, and attackers now combine video marketing, search manipulation, social channels, and low-cost malware tools to reach them at scale.
FAQ
WeedHack is a malware-as-a-service campaign that targets Minecraft players through fake mods, hacked clients, YouTube videos, and search-poisoned websites. Once installed, it can steal passwords, account tokens, Minecraft sessions, crypto wallet data, and other sensitive information.
WeedHack spreads mainly through fake Minecraft mod websites, YouTube videos, links in descriptions and comments, and SEO poisoning. Attackers try to make malicious download pages look like trusted mod or client pages.
Yes. WeedHack can target Minecraft session IDs and account-related data. It can also steal credentials from browsers and other apps, which may put Microsoft, Discord, Steam, Telegram, and crypto wallet accounts at risk.
Stop using the affected device for sensitive accounts, change passwords from a clean device, enable two-factor authentication, run a full security scan, and remove suspicious files and startup entries. If someone threatens you with stolen data or webcam access, do not follow their instructions. Report the incident and ask a trusted adult or security professional for help.
Players should download mods only from trusted platforms or verified developer pages, avoid random links in YouTube, Discord, Reddit, or file-hosting sites, and never disable antivirus protection to run a mod or client.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages