It shouldn’t have been possible for someone to post such malicious JavaScript into a Tumblr post. Our assumption is that the attackers managed to skirt around Tumblr’s [defenses] by disguising their code through Base 64 encoding and embedding it in a data [uniform resource identifier].

Massive worm strikes 8,600 Tumblrs (including ours)