logo

Wikipedia hit by self-propagating JavaScript worm that vandalized pages

ID: c5ecb906-2db0-5398-9227-12f89e540d83

STIX ID: report--c5ecb906-2db0-5398-9227-12f89e540d83

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-03-05

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

The Wikimedia Foundation was hit by a self‑propagating JavaScript worm that injected malicious loaders into both global (MediaWiki:Common.js) and user-level common.js files, vandalizing roughly 3,996 pages and replacing about 85 users' common.js scripts; engineers temporarily restricted editing, reverted changes, and removed the injected code. The dormant malicious test.js (hosted on Russian Wikipedia) appears to have been executed in a logged-in editor's browser, but it remains unclear whether that execution was intentional, accidental, or due to a compromised account.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.