The half of WeedHack that went dark is the half that is cheap to replace. McAfee says the operation pulled its live server address out of the Ethereum blockchain using EtherHiding, a design whose entire purpose is to make the loss of any single host survivable [8]. The vendor nonetheless reports that after its early-July writeup the C2 stopped answering and the renter-facing dashboard vanished [3]. What did not go anywhere is the acquisition layer: pages detailed enough to reproduce a real tool's feature list, FAQ, install steps, developer credits and links back to the genuine GitHub repository [9].
The June figures reward a little division. McAfee logged 116,464 infected systems since January and put daily intake at 2,000 to 3,000 [7]. At that rate the entire cumulative total represents 39 to 58 days of work [1], against roughly five months of operation, so the pace that made the original report alarming belongs to the period after the distribution network matured rather than to the malware's debut. The stealer was never the scarce input.
The 6,300 blocked attempts work out to about 210 a day [2], and that counts only McAfee-protected users bouncing off ten known domains [1][2]. It does not count JAR files hosted on Planet Minecraft and EndMods, both legitimate destinations for Minecraft tools [19], nor the link sprawl on the services doing most of the delivery: Discord at 49.6 percent of catalogued malicious URLs, MediaFire 23.4, GitHub 8.2, Dropbox 4.6 [16], which is 85.8 percent sitting on four platforms users have no reason to distrust [3].
The impersonation succeeds partly because much of the target ecosystem never had a website to impersonate. Nova Client is an open-source project without one, so the attackers built the missing site and ranked it above the repository [13]. McAfee's cleanest tell on that page is a credits section listing generic team names instead of the people who wrote the code [14]. Where a real site does exist, the clone sits on top of it: the first two Google results for "Xenon Client" led to fake sites, according to McAfee [11]. One domain in the set was assembled with the AI website builder Lovable, which puts the cost of the next convincing clone close to zero [15]. Volume is cheap by other routes too, with one Discord channel pushing fake DonutSMP clients carrying more than 1,900 members [17] and a single site listing eight separate mods that all delivered the same malware [18].
None of this is particular to Minecraft. Check Point documented a comparable operation in June 2026 that impersonated open-source and freeware projects and routed visitors through a traffic distribution system to deliver Remus Stealer and other families [21]. McAfee's own advice concedes where the leverage is by being a routing rule rather than a detection one: take mods from the developer's repository or from Modrinth and CurseForge, and read a prompt to disable antivirus as the payload identifying itself [20].