← Wikimedia Foundation

2026 Wikimedia Foundation — self-propagating on-wiki JavaScript worm; read-only lockdown

2026 Unknown records affected Share on X

Data compromised

On-wiki content and editor-session integrity; no Foundation-confirmed PII exfiltration in summarized statements

Technical writeup

In early March 2026, security reporting described a self-replicating JavaScript payload that spread through privileged on-wiki script locations (including MediaWiki:Common.js–class pages), affecting on the order of thousands of pages and hundreds of accounts across Wikimedia projects. The Foundation placed wikis in read-only mode, disabled user-JavaScript, and reverted malicious edits. Public statements highlighted vandalism and integrity impact while indicating no evidence of off-wiki personal-data theft from the Foundation.

Root cause

Malicious user-script content amplified by staff review workflow; worm-like cross-page propagation

References