Self-Replicating Prompt Injection Worm Found in Microsoft Copilot via Word
What
A security researcher demonstrated a self-replicating prompt injection worm targeting Microsoft Copilot for Word: hidden text instructions embedded in a Word document cause Copilot to execute the instructions and copy the payload into newly drafted documents, making each output a new carrier [1]. Microsoft received responsible disclosure roughly 144 days before the July 29, 2026 publication date and has not deployed a fix covering the full attack class [1][2]. Coverage is wide across security media and community forums, with ITNews reporting that Microsoft has been unable to fully eliminate the worm despite apparent partial attempts [3].
Why it matters
The self-replication property removes the need for the original malicious document to remain in circulation — each document Copilot produces becomes an independent carrier, which is how worms spread in enterprise document workflows without user awareness. An unpatched vulnerability of this kind in a widely deployed AI assistant poses a different threat model than prior prompt injection attacks, which required ongoing attacker access.
Open questions
Has Microsoft deployed any partial mitigation, and does it address the propagation mechanism specifically? [3][2]
Has the worm been observed outside a controlled research environment, or does exploitation require specific enterprise Copilot configurations?
Does the same carrier mechanism apply to other AI assistants embedded in document-editing software, beyond Microsoft's ecosystem? [6][7]
Will the researcher publish a full technical paper detailing additional attack variants or payloads beyond the self-replication proof of concept? [1]
Narrative
A security researcher demonstrated a proof-of-concept worm that uses Microsoft Copilot for Word as its propagation vector. The attack embeds hidden text — using techniques such as white-on-white text, previously observed in adversarial AI-targeted résumés — in a Word document. When a Copilot user processes that document, Copilot interprets the hidden text as a user command, executes it, and copies the payload into any new document it drafts in that session. Each output document becomes an independent carrier capable of infecting further documents when processed by other users [1].
The self-replication property distinguishes this from earlier prompt injection attacks, which required the original malicious document to remain in the attacker's control or in active circulation. Simon Willison, reporting on July 29, 2026, identified this as the first documented prompt injection attack deliberately engineered to self-replicate across documents [1]. The disclosure timeline adds weight to the finding: responsible disclosure was sent to Microsoft approximately 144 days before publication — placing it around early March 2026 — and as of the publication date no mitigation covering the full class of attack had been deployed [1][2].
ITNews described Microsoft as unable to "kill" the researcher's worm [3], implying some partial response was attempted but failed to address the underlying mechanism. The Hacker News thread and Reddit discussion amplified the finding within the security community [4][5], with the 144-day gap between disclosure and the absence of a full fix drawing particular attention [2].
The document-borne worm sits within a broader pattern of indirect prompt injection vulnerabilities across Microsoft's AI-integrated product line. Related findings include a patched Copilot Studio prompt injection [6], a GitHub Copilot CVE (CVE-2026-41109) for indirect prompt injection [7], and research on prompt injection in GitHub Actions [8]. The Word worm is the first of these to demonstrate an autonomous propagation mechanism, but the wider attack surface for AI-integrated productivity tools remains under active research.
Timeline
- 2026-03-07: Security researcher submits responsible disclosure of the Copilot for Word worm to Microsoft, approximately 144 days before public publication. [1]
- 2026-07-29: Simon Willison publishes report describing the self-replication mechanism, hidden-text technique, and Microsoft's 144-day non-response. [1]
- 2026-07-31: Wide media coverage follows, including GIGAZINE, CSO Online, AI Governance Institute, and ITNews reporting Microsoft has been unable to fully eliminate the worm. [9][2][10][3]
Perspectives
Simon Willison
Reports the finding with evident concern; frames self-replication as a novel and serious escalation of prompt injection, and criticizes Microsoft's failure to deploy a full fix after 144 days.
Evolution: Consistent — this is the initial report.
The unnamed researcher
Followed responsible disclosure protocol, waited the full 144-day window, then published without a complete patch in place.
Evolution: Consistent — no public reversal on disclosure decision.
Microsoft
Has not deployed a mitigation covering the full attack class as of late July 2026; appears to have made partial attempts that have not resolved the root vulnerability.
Evolution: No public statement on the record; stance inferred from researcher's disclosure account and ITNews reporting.
Security community (Hacker News, Reddit)
Engaged and amplifying; particular focus on the 144-day disclosure gap and the self-replication mechanism as a qualitative step beyond prior prompt injection demonstrations.
Evolution: Consistent with typical security community response to unpatched disclosures.
Tensions
- The researcher published after 144 days of responsible disclosure with no full fix from Microsoft; Microsoft has not publicly addressed the timeline or the scope of remaining exposure. [1][2]
- ITNews reports Microsoft 'can't kill' the worm, implying partial mitigations exist but fail to address the class of attack, while the researcher and Willison describe the full attack as unmitigated. [3][1]
Status: active and growing
Sources
- [1] AI Worming through Word — Simon Willison (2026-07-29)
- [2] Unpatched AI Worm in Microsoft Copilot for Word Can Self-Replicate Through Enterprise Documents After 144-Day Disclosure Window | AI Governance Institute — reactive:copilot-prompt-injection-worm
- [3] Microsoft can't kill dogged researcher's Copilot for Word ... — reactive:copilot-prompt-injection-worm
- [4] Document-borne AI worms can self-propagate through ... — reactive:copilot-prompt-injection-worm
- [5] Microsoft Copilot Vulnerability Allows Self-Propagating AI ... — reactive:copilot-prompt-injection-worm
- [6] Microsoft patched a Copilot Studio prompt injection. The ... — reactive:copilot-prompt-injection-worm
- [7] GitHub Copilot CVE-2026-41109: Indirect Prompt Injection ... — reactive:copilot-prompt-injection-worm
- [8] Prompt Injection in AI-Powered GitHub Actions — reactive:copilot-prompt-injection-worm
- [9] A document-based, self-replicating AI worm targeting Microsoft Word's Copilot has been demonstrated for the first time. - GIGAZINE — reactive:copilot-prompt-injection-worm
- [10] Copilot worm can spread through Microsoft Word docs — reactive:copilot-prompt-injection-worm