Wikipedia hit by self-spreading JavaScript worm that defaced pages.
Mar 6, 2026 // 00:09 - Norina Velotta


On March 5, 2026, Wikipedia and its sister projects were placed in read-only mode for approximately two hours following a site-wide attack by a self-propagating JavaScript worm. The incident stemmed from a malicious script that had remained dormant on the Russian Wikipedia since 2024 before being accidentally triggered by a Wikimedia Foundationstaff member during a security review.

The Incident at a Glance

  • Trigger: A staff member with global interface administrator rights accidentally loaded the dormant code while testing global API limits.
  • Mechanism: The worm targeted MediaWiki:Common.js, a critical file loaded by every visitor. Once active, it hijacked the accounts of logged-in administrators who viewed the infected pages.
  • Vandalism: The script performed mass deletions using the Special:Nuke tool and replaced article content with the Russian phrase “Закрываем проект” (“Closing the project”).
  • Propagation: It attempted to inject itself into other site-wide and personal JavaScript files to create an instant, exponential propagation loop.

Impact and Response

  • Read-Only Mode: To halt the spread, all Wikimedia wikis were temporarily locked, and user-authored JavaScript was disabled across the platform.
  • “Blinding” Admins: The worm used jQuery to hide interface elements from administrators, effectively preventing them from manually reverting changes while it operated in the background.
  • Origins: The code was traced back to a 2023 attack on alternative Russian wikis and had been sitting undetected on Wikipedia for 1.5 years.

The Wikimedia Foundation confirmed that the issue was resolved by removing the malicious code and has since restored full editing capabilities.

#by self-spreading  #javascript  #news  #that defaced pages.  #wikipedia hit  #worm   —   News