Everyone in the comments saying to use CurseForge is seemingly unaware that malware is very easy to put inside a mod and get verified, seen a few payload grabber mods so far and they weren't even trying to hide it to anyone who bothered to take the smallest look inside the jar.
More than 116,000 Minecraft players have reportedly been infected by malware hidden inside fake mods and cheats since January 2026.
The malware, known as WeedHack, spreads through fake download sites, YouTube videos, and manipulated search results that trick players into installing infected files instead of legitimate Minecraft content.
According to security researchers, the malware can:
- Steal passwords and account credentials
- Collect personal and system information
- Take screenshots of a victim’s device
- Give attackers remote access to infected computers
- Allow webcam monitoring and keylogging through paid plans
What makes the campaign particularly alarming is its low cost.
For around $5 per month, cybercriminals can subscribe to the service and gain access to spying and surveillance features.