Drooid Logo
Back to story perspectives

Full Breakdown

Wikimedia Foundation Faces Security Incident from Dormant JavaScript Worm

3/10/2026, 2:06:15 AM

Overview of the Security Incident

The Wikimedia Foundation encountered a significant security incident involving a self-propagating JavaScript worm that affected multiple wikis, including Wikipedia. The incident was triggered when a malicious script, initially uploaded to the Russian-language Wikipedia in March 2024, was inadvertently activated by a security engineer during a routine review of user scripts. This activation led to a temporary lockdown of Wikipedia's editing capabilities as the worm spread and vandalized pages.

Details of the Worm's Activation

The malicious script, named test.js and uploaded by the account Ololoshka562, remained dormant for nearly two years before being activated. Upon execution, it functioned as a classic worm, injecting itself into the global JavaScript of each page it accessed and propagating into the personal user scripts of logged-in users. The worm executed commands that deleted random articles using the Special:Nuke tool, which is typically used by administrators to batch-delete pages. The deletions were accompanied by the Russian phrase "????????? ??????," meaning "We are closing the project."

Approximately 3,996 pages were modified, and around 85 users had their common.js files overwritten before Wikimedia engineers restricted editing to investigate and revert the changes. The incident lasted for about 23 minutes, during which no permanent damage was inflicted on the articles, and personal data remained secure.

Official Responses and Statements

In response to the incident, the Wikimedia Foundation stated, "During that review, we activated dormant code that was then quickly identified to be malicious. The code was active for 23 minutes… it did not cause permanent damage. We have no evidence that Wikipedia was under attack or that personal information was breached." The Foundation acknowledged the process failure that allowed the worm to exploit unvetted community scripts without adequate sandboxing, which is crucial for preventing such incidents.

Criticism and Concerns

The incident has raised concerns regarding the security protocols in place for managing user-contributed code on open platforms like Wikipedia. Critics argue that the lack of proper sandboxing and oversight allowed the worm to thrive undetected for an extended period. Observers have drawn parallels between the worm's tactics and historical vandalism campaigns associated with Russian-language Wikipedia, suggesting it may be part of a broader effort to disrupt the platform.

What's Next for Wikimedia

In light of this incident, the Wikimedia Foundation is developing additional security measures to prevent similar occurrences in the future. The focus will be on enhancing the auditing processes for user-contributed code and implementing stricter controls to ensure that dormant scripts do not pose a risk to the platform.

Verbatim Quotes

  • “During that review, we activated dormant code that was then quickly identified to be malicious. The code was active for 23 minutes… it did not cause permanent damage. We have no evidence that Wikipedia was under attack or that personal information was breached.” — Wikimedia Foundation