ARTFEED — Contemporary Art Intelligence

Self-Replicating Prompt Injection Worm Targets Microsoft Word via Copilot

ai-technology · 2026-07-29

Security researcher Håkon Måløy has developed a novel prompt injection attack against Microsoft Word that creates self-replicating worms. The attack embeds hidden instructions in a document; when that document is used as source material in Copilot for Word, the AI may interpret the instructions as part of the user's request, manipulating the document being edited. Critically, Copilot may copy the hidden instructions into the output document, turning it into a new carrier. If that carrier is later used in another Copilot-assisted workflow, the instructions propagate further without needing the original attacker document. This technique builds on known white-on-white text tricks but is the first to deliberately self-replicate. Måløy responsibly disclosed the vulnerability to Microsoft, which had 144 days to develop a fix, but no comprehensive mitigation exists yet. The discovery was posted by Simon Willison on 29 July 2026.

Key facts

  • Håkon Måløy discovered a self-replicating prompt injection worm for Microsoft Word.
  • Hidden instructions in a document can be interpreted by Copilot as part of the user's request.
  • Copilot may copy the hidden instructions into the output document, creating a new carrier.
  • The worm can propagate to further documents without the original attacker document.
  • This is the first known prompt injection attack that deliberately self-replicates.
  • Måløy responsibly disclosed the vulnerability to Microsoft.
  • Microsoft had 144 days to work on a fix but no full mitigation exists.
  • Simon Willison posted the link on 29 July 2026.

Entities

Institutions

  • Microsoft
  • Copilot for Word

Sources