March 2026 security journalism detailed a self-propagating JavaScript incident across Wikimedia projects: privileged on-wiki scripts were abused to insert loaders into large numbers of pages, prompting read-only lockdowns, temporary user-JS disablement, and mass reverts. Wikimedia Foundation staff stressed vandalism and content-integrity risk while stating they did not see evidence of off-platform theft of contributor PII.
Canonical record: Wikimedia JS worm 2026 on BreachHistory.
Sources: BleepingComputer, SC Media