The Wikimedia Foundation responded to a security incident in which a self-propagating JavaScript worm vandalized pages and modified user scripts across multiple wiki projects, including Wikipedia. Editors reported waves of automated edits that inserted hidden JavaScript loaders and random vandalism, prompting Wikimedia engineers to temporarily restrict editing while investigating and reverting malicious changes.
Reporting indicates the outbreak began after a malicious script hosted on Russian Wikipedia (notably User:Ololoshka562/test.js, previously uploaded and allegedly tied to earlier wiki attacks) was executed, leading to infection of both user-level and global JavaScript. The worm propagated by injecting loaders into User:<username>/common.js and the global MediaWiki:Common.js, enabling it to run in other editors’ browsers and spread further when accounts with sufficient privileges were affected. Approximately 3,996 pages were modified and about 85 users had their common.js overwritten before containment actions and mass reverts began; it remains unclear whether the initial execution was accidental testing activity, intentional, or the result of account compromise.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Wikimedia staff rolled back affected scripts, suppressed modified pages from change histories, removed the injected code, and restored editing access. At the time of reporting, no detailed post-incident report had yet been published.
Editors first noticed the malicious activity on Wikipedia's Village Pump (technical), prompting Wikimedia engineers to investigate, revert changes, and temporarily restrict editing across affected projects.
The self-propagating worm spread across Wikimedia projects, editing random pages to insert vandalism and hidden JavaScript loaders while replacing about 85 users' common.js files. Reporting estimated that roughly 3,996 pages were modified.
A malicious user script hosted on Russian Wikipedia, identified as User:Ololoshka562/test.js, was executed in editors' browsers and began propagating by overwriting users' common.js files and, where privileges allowed, the global MediaWiki:Common.js.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.