A security researcher has documented what may be the first public example of a document-borne "AI worm" self-propagating through a mainstream productivity suite, showing that hidden malicious instructions can hop from one Microsoft Word file to another via Copilot for Word.

In a coordinated disclosure published on July 28, researcher Håkon Måløy described how attacker-controlled instructions embedded in a document can hijack Copilot's drafting. Once the AI reads the poisoned document, it can silently alter the output — for example, halving financial figures in a report — and then copy the full malicious payload into the newly generated file, concealed as white text. That new file becomes a carrier, infecting further documents the next time it is used as source material, even after the original malicious file is gone. For more context on this story, see our ongoing more AI stories.

The work was conducted with Microsoft's Security Response Center (MSRC) over a 144-day coordination period. According to the disclosure, Microsoft shipped multiple fixes, including an upgrade of the underlying model to GPT-5.5 and then GPT-5.6, but the researcher reproduced the complete attack chain with every mitigation deployed. "The vulnerability class therefore remains exploitable at the time of publication," Måløy wrote.

The findings highlight a deeper architectural problem in LLM-based systems. Because a language model must read external content to decide whether it is relevant or hostile, "the content being inspected participates in the act of inspection" — making reliable prompt-injection defences elusive.

Microsoft mitigated the specific payloads reported and closed the memory and email vectors from earlier parts of the series, but acknowledged no complete fix exists for the broader class. The researcher recommends treating externally sourced documents as untrusted when used with Copilot and carefully reviewing AI-generated content before reuse or distribution.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →