How AI Website Builders Are Becoming Tools for Cybercriminals
Cybersecurity researchers have discovered that Lovable, an artificial intelligence-powered website builder, was used to create at least one malicious site distributing Weedhack malware to unsuspecting gamers. The finding highlights a troubling trend: as AI tools become easier to use and more widely available, they're simultaneously making it simpler for attackers to launch convincing phishing and malware distribution campaigns at scale.
What Is Weedhack and How Does It Spread?
Weedhack is a malware family that targets gamers by masquerading as legitimate Minecraft clients and modification tools. McAfee Labs detected and blocked more than 6,300 attempts to access malicious sites hosting the malware. The attack begins with SEO poisoning, a technique where attackers manipulate search engine rankings to make fake websites appear at the top of results for popular tools. When users click on these spoofed sites, they download infected files that can steal system information, disable Microsoft Defender security protections, and harvest sensitive data from compromised computers.
The malware was first documented in June 2026, and researchers found that attackers were using YouTube and SEO manipulation to redirect traffic to bogus domains. What makes this campaign particularly effective is the sophistication of the fake websites themselves. Attackers created lookalike gaming websites that replicate legitimate projects down to the smallest detail, including branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories.
How Are Attackers Using AI Website Builders?
One of the most striking discoveries in McAfee Labs' investigation was that at least one malicious domain, kryptonclientcrack.lovable.app, was built using Lovable, the AI-powered website builder. This revelation underscores a critical vulnerability in the democratization of web development tools. Lovable allows users to create professional-looking websites quickly and with minimal technical expertise, which is valuable for legitimate businesses and creators. However, the same ease of use makes it trivial for attackers to spin up convincing phishing and malware distribution sites in minutes rather than hours.
The use of Lovable to host malware distribution infrastructure is not an isolated incident but rather a symptom of a broader problem: as AI tools lower the barrier to entry for web development, they simultaneously lower the barrier for cybercriminals. Attackers no longer need deep technical knowledge to create sites that look legitimate and trustworthy.
What Distribution Channels Are Attackers Using?
McAfee Labs researchers found that attackers are leveraging multiple platforms to spread Weedhack, creating a multi-channel distribution network that makes the malware harder to contain. The data reveals a clear pattern of how attackers exploit trusted platforms:
- Discord Links: Nearly half of all malicious URLs identified (49.6%) were Discord links, making the messaging platform the primary distribution vector for malware.
- File Hosting Services: MediaFire accounted for 23.4% of malicious URLs, allowing attackers to host and share infected JAR files without hosting their own infrastructure.
- GitHub Repositories: GitHub represented 8.2% of malicious URLs, with attackers creating fake repositories that mimic legitimate Minecraft projects.
Beyond these primary channels, attackers are also distributing Weedhack through legitimate Minecraft modding platforms like Planet Minecart and EndMods, which host tools and enhancements for the game. This approach is particularly insidious because it exploits the trust users place in established modding communities.
Which Fake Minecraft Clients Are Distributing the Malware?
Researchers identified multiple fake domains designed to impersonate popular Minecraft clients and tools. In many cases, these spoofed websites rank higher in search results than the legitimate projects they're copying, meaning unsuspecting users find the malicious versions first:
- Glazed Client Impersonation: glazed-client.com replicates glazedclient.com, a free and open-source Minecraft add-on.
- Radium Client Impersonation: radium-client.com replicates radiumclient.com, a paid Minecraft client.
- Seed Cracker Impersonation: seedcrackerx.github.io replicates seedcrackerx.com, a Minecraft seed cracking software tool.
- Cheatlib Impersonation: cheatlib.xyz claims to be a "modern Minecraft mod library" with more than 1.6 million downloads.
- Meteor Client Impersonation: meteorclients.com replicates meteorclient.com.
- Nova Client Impersonation: nova-client.com impersonates an open-source Minecraft client that ranks at the top of search results across Google, Microsoft Bing, Brave Search, and DuckDuckGo.
- Xenon Client Impersonation: xenoclient.lol and xenonclient.com impersonate Xenon client, another tool that appears prominently in search rankings.
The fact that both Xenon Client and Nova Client's fake websites feature at the top of search results across multiple search engines demonstrates the effectiveness of SEO poisoning as an attack vector. Users searching for these tools are more likely to find the malicious versions than the legitimate ones.
"Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware," stated Aayush Tyagi, researcher at McAfee Labs.
Aayush Tyagi, Researcher at McAfee Labs
How to Protect Yourself From Weedhack and Similar Malware?
- Verify Official Sources: Always download Minecraft clients and mods from official GitHub repositories or established modding platforms like Modrinth. Check the URL carefully before downloading, as attackers often use domains that look similar to legitimate ones.
- Keep Your System Updated: Ensure your operating system and security software are fully patched and up to date. McAfee Labs recommends keeping devices current with the latest security updates to prevent exploitation of known vulnerabilities.
- Scan Files Before Opening: Use antivirus or antimalware software to scan any downloaded files before executing them. This simple step can catch many known malware variants before they infect your system.
- Be Cautious of Security Prompts: Exercise extreme caution when any mod or cheat tool prompts you to disable security protections before installation. Legitimate software should never ask you to weaken your defenses.
- Use Search Engine Verification: When searching for tools, cross-reference multiple sources and verify that the website URL matches what you expect. Attackers often register domains with slight variations in spelling.
Why Does This Matter Beyond Gaming?
The Weedhack campaign is not an isolated incident but rather part of a larger trend of attackers using SEO poisoning and AI-powered tools to distribute malware at scale. In June 2026, Check Point flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework.
The use of Lovable to host malware distribution infrastructure is particularly significant because it demonstrates how AI tools designed to democratize web development are being weaponized by criminals. As these tools become more accessible and easier to use, the barrier to entry for launching sophisticated phishing and malware campaigns continues to drop. This creates a cat-and-mouse game where security teams must work harder to identify and block malicious sites, while attackers can create new ones faster than ever before.
For users, the lesson is clear: trust should never be placed solely in search engine rankings or website appearance. Verify sources independently, use security software, and remain skeptical of any tool that asks you to disable your protections.