Over 116,000 Mincraft systems infected in WeedHack malware campaign
McAfee says WeedHack has infected 116,464 systems since January by hiding in fake Minecraft mods and clients pushed through YouTube and search poisoning.
Intelligence analysis by GPT-5.4 Mini

WeedHack is a malware-as-a-service infostealer built around fake Minecraft downloads. McAfee says the campaign has spread through misleading videos and poisoned search results, infecting more than 116,000 systems and stealing credentials, wallet data, and screenshots.
A fake Minecraft download turned out to be a sneaky thief. It spread through videos and search results, then stole passwords and game logins from many computers, like a toy box with a hidden trapdoor.
Analysis
How the campaign spreads
McAfee says WeedHack is being delivered through Minecraft-related malicious mods, clients, cheats, and utilities. The main lures are YouTube videos and SEO poisoning, with attackers posting download links in video descriptions and comments or pushing fake download sites through search results.
Some of the videos appear polished and use voice-over narration to look legitimate. McAfee says a few have attracted more than 7,500 views, which shows the campaign is reaching real users rather than sitting idle on obscure pages.
What WeedHack does
The operation works like malware-as-a-service. According to McAfee, the platform offers a dashboard where customers can view victims, stolen information, and infected device profiles. It also includes a payload builder for Minecraft versions 1.21.0 through 1.21.10.
The free tier focuses on stealing Minecraft session IDs, browser cookies, saved passwords, Discord, Steam, and Telegram credentials, plus data from dozens of browsers, cryptocurrency add-ons, and wallet apps. It can also capture screenshots. A paid tier adds remote control, webcam access, keylogging, remote shell access, and remote file management.
Scale and targeting
McAfee telemetry shows 116,464 impacted systems, with infections averaging 2,000 to 3,000 per day. The researchers say the campaign uses more than 240 distribution URLs and 3,820 unique malicious JAR files. Most victims are in the United States, Germany, India, and the UK.
McAfee’s advice is straightforward: only trust mods from official project sources, verify download links, and be cautious with JAR files from questionable sites. For players who want add-ons, the Minecraft Marketplace is the safer option.
Key points
- McAfee says WeedHack has infected 116,464 systems since January.
- The malware is spread through fake Minecraft mods, clients, cheats, and utilities.
- Attackers use YouTube descriptions/comments and SEO poisoning to drive downloads.
- WeedHack steals credentials, session IDs, cookies, screenshots, and wallet data.
- A premium tier adds remote access, keylogging, webcam access, and file control.
If users stick to official project sources and verify links, this campaign can lose a major part of its reach. McAfee’s reporting also gives defenders concrete indicators to watch for, including the distribution URLs and malicious JAR files.
If the lures keep working, more players may install fake mods and hand over logins, wallet data, or chat accounts. The premium features described by McAfee also mean the same infection path can be used for harassment, spying, and broader account compromise.



