The Hallway Track
Engineering Insights

AI Worming through Word

Simon Willison · Jul 29, 2026 · Engineering Insights

Researcher demonstrates self-replicating prompt injection worm spreading through Microsoft Word via Copilot

“An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user's request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier.”

Researcher Håkon Måløy discovered a self-replicating prompt injection attack against Microsoft Copilot for Word, where hidden instructions in a document can propagate automatically into subsequent documents through Copilot-assisted workflows. This represents a meaningful escalation of prompt injection severity — from single-document manipulation to persistent, autonomous spread across document pipelines. Microsoft was given 144 days after responsible disclosure but has not yet produced a mitigation covering the full attack class.

prompt-injection microsoft-copilot security llm-security worm word

Watch / read the original source →