Håkon Måløy has demonstrated that a self-spreading worm can hide inside Microsoft Word documents and hijack Microsoft Copilot. The attack relies on prompt injection where malicious instructions appear as white text on a white background with a tiny font size. Human readers cannot see this content, but the AI strips those visual properties before processing the file. When a user asks Copilot to generate content based on that document, the model executes the hidden commands and writes them into the new output. This new file then acts as a carrier, allowing the infection to replicate whenever someone uses it as a template or source for further reports.
The situation escalated after Microsoft confirmed the behaviour on March 31. Two separate fix attempts failed to stop the worm, and the company has not released a patch after 144 days. Måløy published his findings without providing the actual payload text to prevent immediate misuse. This development validates concerns raised by researcher Andreas Kirsch regarding the tangible risks of prompt injection. The attack proves that unsolved security vulnerabilities in AI tools can spread autonomously through standard office workflows.
* Microsoft failed to patch the vulnerability after 144 days
* Visual obfuscation hides instructions from human eyes
* The worm replicates when documents are used as templates




