A hidden prompt in a Word document self-propagates through Microsoft Copilot for Word
2026-copilot-word-prompt-injection-worm · 2026-07-29
A researcher demonstrated a self-propagating prompt-injection attack: a JSON-formatted prompt hidden as white-on-white text in a Word document is read by Copilot for Word as an instruction. Copilot then appends the same hidden prompt to the document it edits, turning each new document into a carrier that reinfects the next Copilot user.
System
- Framework
- Microsoft 365 Copilot for Word
- Tools
- word, copilot
- Vendor
- Microsoft
- Autonomy
- human-in-the-loop
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → memory-context-poisoning/rag-poisoning
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
An attacker hides a JSON-formatted prompt as white text on a white background inside a Word document. When a user asks Copilot for Word to draft or edit based on that document, Copilot strips the formatting, reads the hidden text, and treats the embedded instructions as part of the request — then modifies the active document and appends the full malicious prompt back as hidden white text, making that document a new carrier.
Root cause
Copilot processes hidden document content as trusted instructions and can write attacker-controlled content back into the document. Because the produced document is later used as source material for other Copilot sessions, the injection self-replicates from document to document.
Contributing factors
- Hidden (white-on-white) document text is consumed as instructions, not treated as untrusted data.
- The assistant writes attacker-controlled content back into the document it edits.
- Produced documents feed later Copilot sessions, enabling self-propagation.
Detection
Discovered by security researcher Håkon Måløy, reported to Microsoft on 2026-03-06 and published after a 144-day coordinated disclosure with MSRC.
Recovery
Microsoft acknowledged the behaviour, applied multiple mitigations during the disclosure period, and upgraded Copilot's underlying model; the researcher reported the broader attack class still reproduced, with no comprehensive mitigation at publication.
Prevention
Treat retrieved/hidden document content as untrusted data, not instructions; strip or neutralise hidden text before it reaches the model; prevent the assistant from writing hidden instruction payloads into documents; isolate document content from the instruction channel.
Blast radius
- Data
- A self-propagating prompt injection able to carry arbitrary instructions between documents via Copilot for Word. unknown
- User harm
- Demonstrated as a proof of concept; no in-the-wild exploitation was reported. none-reported
- Scope
- users of Microsoft Copilot for Word
- Reversibility
- irreversible
References
- OWASP LLM
- LLM01 LLM04
- MITRE ATLAS
- AML.T0051
- Tags
- prompt-injection self-propagating copilot word document-worm
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-copilot-word-prompt-injection-worm/
@misc{2026-copilot-word-prompt-injection-worm,
title = {A hidden prompt in a Word document self-propagates through Microsoft Copilot for Word},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-copilot-word-prompt-injection-worm/}
}