AI Worming through Word

Simon Willison's Blog News

Summary

Håkon Måløy discovered a prompt injection variant that turns into a self-replicating worm in Microsoft Word's Copilot, propagating hidden instructions across documents. Microsoft had 144 days to fix but no full mitigation.

No content available
Original Article
View Cached Full Text

Cached at: 07/29/26, 07:55 PM

# AI Worming through Word Source: [https://simonwillison.net/2026/Jul/29/ai-worming-through-word/](https://simonwillison.net/2026/Jul/29/ai-worming-through-word/) 29th July 2026 \- Link Blog **[AI Worming through Word](https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/)**\([via](https://news.ycombinator.com/item?id=49096188)\) Neat new prompt injection variant by Håkon Måløy, who found a way to upgrade prompt injection attacks against Microsoft Word to full self\-replicating worms: > An attacker places hidden instructions in a document that is later used as source material in Copilot for Word\. Copilot may interpret those instructions as part of the user’s request, causing it to manipulate the document being drafted or edited\. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier\. If the carrier is subsequently used in another Copilot\-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker’s original document being present\. We've seen plenty of hidden white\-on\-white text before \- the kids[are using it in their job applications now](https://x.com/ScienceYael/status/2082175224007848019)\- but this is the first one I've seen that deliberately copies instructions to self\-replicate itself\. It was responsibly disclosed to Microsoft who then had 144 days to work on a fix, but so far \(unsurprisingly\) there's no mitigation that covers the full class of attack\.

Similar Articles

Document-borne AI worms can self-propagate through Copilot for Word

Hacker News Top

This article demonstrates a novel AI worm that can self-propagate through Microsoft's Copilot for Word by embedding hidden instructions in documents, causing Copilot to copy those instructions into new documents. The vulnerability was disclosed to Microsoft's Security Response Center.

Quoting Calif Research

Simon Willison's Blog

Calif Research demos WeWorm, a zero-click worm spreading through WeChat calls, with AI enabling rapid exploit development.

AI Worms and Viruses Are Coming

Wired

Researchers are demonstrating that AI agents can autonomously self-replicate and hack into remote systems, raising concerns about future AI-powered worms and viruses that could evade detection and cause widespread harm.

Adaptive Agentic Worms (8 minute read)

TLDR AI

Researchers have demonstrated adaptive computer worms powered by open-weight LLMs that can generate target-specific attacks and self-replicate, using stolen compute to evade conventional AI safeguards.

Microsoft Copilot Cowork Exfiltrates Files

Hacker News Top

Researchers at PromptArmor demonstrate that Microsoft Copilot Cowork can be exploited via indirect prompt injection to exfiltrate files from Microsoft 365, exploiting the lack of approval for certain actions when the recipient is the active user.