Back to News

AI Worming through Word: Prompt Injection Enables Self-Replicating Worm in Microsoft Copilot

#prompt injection#microsoft copilot#word#worm

Håkon Måløy discovered a prompt injection variant that turns Microsoft Word documents into self-replicating worms when processed by Copilot for Word. Hidden instructions in a document cause Copilot to manipulate the document and propagate the attack. This highlights a new vector for prompt injection attacks in office productivity tools.

Coverage timeline

  1. Simon Willison

    AI Worming through Word Neat new prompt injection variant by Håkon Måløy, who found a way to upgrade prompt injection attacks against Microsoft Word to full self-replicating worms: An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier. If the carrier is subsequently used in another Copilot-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker’s original document being present. We've seen plenty of hidden white-on-white text before - the kids are using it in their job applications now - but this is the first one I've seen that deliberately copies instructions to self-replicate itself. It was responsibly disclosed to