MechanismArticle
A carrier document, when used in subsequent Copilot-assisted workflows, triggers the hidden instructions again and propagates them into further documents even without the attacker's original document being present.
Once infected, a document becomes a carrier that propagates the hidden instructions through any future Copilot workflow that uses it, removing dependence on the original attacker document. ✦ AI generated
Article author · Simon Willison's Weblog · 2026-07-29 · original ↗
If the carrier is subsequently used in another Copilot-assisted workflow, the instructions can trigger again and propagate into further documents, even without the attacker's original document being present.
Read full article ↗excerpt · fair-use quotation
Around this claim
Context · 2
While hidden white-on-white text is a known technique, this attack is the first to deliberately copy instructions into outputs to achieve self-replication.Article author · Simon Willison's Weblog · conf 85%The vulnerability was responsibly disclosed to Microsoft 144 days ago with no mitigation that covers the full class of attack produced so far.Article author · Simon Willison's Weblog · conf 70%
This moment responds to
explains mechanism → Håkon Måløy discovered a prompt injection variant against Microsoft Word that achieves full self-replicating worm behavior.Article author · Simon Willison's Weblogextends → An attacker places hidden instructions in a source document that Copilot for Word interprets as part of the user's request, causing it to manipulate the document being edited and copy the instructions into the output, turning that output into a new carrier document.Article author · Simon Willison's Weblog