
On March 5, 2026, Wikipedia and its sister projects were placed in read-only mode for approximately two hours following a site-wide attack by a self-propagating JavaScript worm. The incident stemmed from a malicious script that had remained dormant on the Russian Wikipedia since 2024 before being accidentally triggered by a Wikimedia Foundationstaff member during a security review.
The Incident at a Glance
MediaWiki:Common.js, a critical file loaded by every visitor. Once active, it hijacked the accounts of logged-in administrators who viewed the infected pages.Special:Nuke tool and replaced article content with the Russian phrase “Закрываем проект” (“Closing the project”).Impact and Response
The Wikimedia Foundation confirmed that the issue was resolved by removing the malicious code and has since restored full editing capabilities.
#by self-spreading #javascript #news #that defaced pages. #wikipedia hit #worm — News
© Bulletproof Servers. All rights reserved.