Minecraft Mods Now Feed a Credential-Theft Service

WeedHack has moved past being a bad mod lure. It is now a managed credential-theft and remote-access service, so the risk is not one fake download but a repeatable pipeline that turns gaming trust into stolen logins and live control of infected systems. McAfee says the campaign has run since January 2026 and uses YouTube, SEO poisoning, and mod/client impersonation to pull victims toward malicious downloads. The operation now has 3,820 unique malicious JARs, more than 240 distribution URLs, and a web dashboard where customers can view stolen credentials, system data, and remote access, with custom payloads for Minecraft 1.21.0 to 1.21.11. The service model lowers the barrier for attackers and keeps the problem alive after any single page or video is removed. With active infections rising by about 2,000 to 3,000 per day, this is a broad trust abuse problem for anyone who downloads software from gaming channels, search results, or creator pages.

Part of the PlainSec briefing for 2026-06-04

Sources