A worm-like attack in Microsoft Copilot for Word has turned a long-running AI security concern into a concrete demonstration
A security researcher has shown that hidden prompt injections inside Microsoft Word documents can spread from file to file when people use Microsoft Copilot for Word to reuse or summarize content. The result is not just a one-off exploit, but a self-propagating mechanism that can turn ordinary documents into carriers.
According to the reported findings, the attack works by embedding instructions in a document in ways that human readers are unlikely to notice, such as white text on a white background at extremely small font size. The researcher says Copilot strips away color and font-size formatting before processing the text, which means the hidden instructions remain visible to the AI system even when they are effectively invisible to the person viewing the document.
That distinction matters because it creates a gap between what a user believes is in a file and what the AI assistant actually reads. If Copilot follows the concealed instructions while generating a new document, the injected text can be copied into that output. The new file then becomes another carrier. When that second document is later used as source material, the same hidden instructions can fire again.
Why this demonstration matters
Prompt injection has often been described as an unsolved problem in AI systems, but many discussions stay abstract. This case is more specific and more unsettling because it shows how the weakness could move through normal office workflows. A malicious file does not have to trick a user into running code in the traditional sense. It only has to be used in the kinds of document-handling tasks that knowledge workers perform every day.
The reported scenario illustrates how an infected market analysis downloaded from the internet could influence a financial report created with Copilot. If the report inherits the hidden instructions, it can then contaminate later drafts, derivative summaries, or template-based documents. In other words, the productivity feature that makes documents easy to repurpose also creates a path for the attack to persist.
This is a notable shift from classic phishing or macro malware. The risk described here is tied to how an AI model interprets language inside trusted business content. The underlying document may look harmless, pass casual inspection, and still alter downstream outputs.
Microsoft was notified, but no fix was in place when the findings were published
The researcher behind the attack, Hakon Maloy, reported the behavior to Microsoft on March 31, according to the source material. Microsoft confirmed the behavior, but two attempted fixes reportedly failed. After 144 days, Maloy published the findings without releasing the payload text itself.
That timeline is important for two reasons. First, it suggests the issue is not merely theoretical or the product of a misunderstood edge case. Second, it reinforces how difficult prompt-injection problems can be to solve in systems built to ingest and transform natural language. If the assistant is expected to read everything in a document as potentially useful context, distinguishing legitimate instructions from malicious ones becomes technically and product-wise complex.
The publication of the findings without a public fix also raises pressure on enterprise AI vendors. Copilot and similar tools are increasingly pitched as assistants for drafting, editing, summarizing, and synthesizing information across a company’s internal files. That makes trust in document boundaries and instruction handling central to product safety.
An office productivity problem, not just an AI lab problem
One reason this case stands out is that it lands in a widely used productivity context rather than a narrowly scoped chatbot interface. Word documents are routinely shared across teams, departments, partners, and external sources. Many organizations are actively encouraging employees to feed more of those documents into AI copilots to save time.
The exploit described in the report suggests that convenience can also become an attack surface. A user may not need to click a dangerous attachment, enable macros, or install suspicious software. Instead, the act of asking Copilot to help write a new document from an old one could be enough to replicate hidden instructions.
That makes defensive habits harder to define. Traditional security guidance often centers on visible warning signs or executable content. Here, the risky material is plain text that has simply been formatted to evade human attention while remaining legible to the model. The attack therefore exploits a mismatch between human and machine perception inside the same file.
What the demonstration says about the state of AI security
The broader takeaway is that prompt injection remains unresolved in real products, especially where models are granted broad authority to interpret mixed-trust inputs. Hidden instructions in external documents, web pages, emails, or attachments are a known concern across AI systems. This example adds a propagation mechanism that makes the problem harder to contain once a bad document enters a workflow.
The report also undercuts the idea that prompt injection is mostly a nuisance that produces odd answers. In this case, the danger is operational. A malicious instruction can survive inside normal business artifacts and spread through routine knowledge work. Even without destructive code execution, that creates integrity risks for reports, summaries, planning documents, and other records that employees may trust.
The researcher’s choice to withhold the actual payload text slightly limits immediate copycat use, but the published description is enough to show the class of failure. For companies evaluating AI copilots, the lesson is straightforward: document ingestion cannot be treated as safe simply because the source looks like ordinary office content.
As enterprises deepen their reliance on AI writing tools, the boundary between content and command is becoming one of the most important security lines to defend. This demonstration shows that, in current systems, the line is still too easy to blur.
This article is based on reporting by The Decoder. Read the original article.
Originally published on the-decoder.com







