A security researcher has developed a self-spreading worm that hides inside Microsoft Word documents and hijacks Copilot, demonstrating a critical vulnerability in AI-powered tools. Håkon Måløy, the researcher, described an attack that uses prompt injection to spread autonomously. The worm hides instructions in a document using white text on a white background with a tiny font size. Readers cannot see the text, but Copilot processes it by stripping color and font size. When someone uses the document as a source, Copilot runs the hidden instructions and copies them into a new file, which becomes a carrier of the attack. This allows the worm to replicate and spread further, potentially manipulating financial reports and infecting additional documents.

Microsoft confirmed the behavior of the worm on March 31, 2026, but two attempts to fix the issue failed. After 144 days without a solution, Måløy published his findings without revealing the payload text. He is holding back the payload to prevent misuse. AI researcher Andreas Kirsch recently joked about the need for such a worm to convince skeptics of AI security risks. Now, the attack exists and highlights the ongoing challenge of prompt injection attacks in AI systems.

The researcher’s findings underscore the persistent threat of prompt injection attacks, which remain an unresolved issue in AI security. The vulnerability in Copilot for Word demonstrates how AI tools can be exploited for malicious purposes, raising concerns about the safety and reliability of AI-driven applications.

Source: thedecoder