Expert warns this dangerous Microsoft Word worm can burrow into Copilot and cause havoc — here's what we know
A copilot-enabled exploit?
by https://www.techradar.com/uk/author/rahim-amir · TechRadarNews By Rahim Amir Published 1 August 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Instructions hidden as white text in a Word document can make Microsoft 365 Copilot silently alter the file it is drafting and copy the instructions into the output
- Each poisoned document becomes a carrier, so the attack spreads through ordinary internal workflows without the original malicious file and needs no macros, malware, or code execution
- Microsoft has shipped two mitigations across a 144-day disclosure, including a model upgrade, and the attack was still reproducible by the researcher
A security researcher has published a proof of concept showing that instructions hidden inside a Word document can cause Microsoft 365 Copilot to silently alter the file it is drafting, then copy those same instructions into the finished document, so the next person to use it becomes a carrier too.
Håkon Måløy, a data scientist with a doctorate in applied machine learning, disclosed the technique as the third installment of his Context Collapse series, after a 144-day coordinated disclosure with the Microsoft Security Response Center.
The reason this is being reported ahead of a fix is that it still works despite multiple attempts by Microsoft, as he notes that no robust mitigation for the broader vulnerability class is currently available.
Latest Videos FromTechRadarWatch full video here:
A clever attack designed around Copilot's approach to text
The underlying attack belongs to a family known as cross-domain prompt injection, or XPIA. An attacker writes instructions in a natural-language document, formats them as white text on a white background at a small point size, and shares the file.
Because Copilot for Word strips formatting before passing text to the underlying language model, the model reads text the human never sees. This is true even for documents that are not opened by the user on purpose: The attack can trigger either when a user manually attaches a document to Copilot or when Copilot, working in Work IQ mode, searches the user's OneDrive for relevant files and finds the malicious one on its own.
It is also more dangerous than other exploits because of one key element: propagation. The hidden prompt in Måløy's proof of concept had two parts. One instructed Copilot to alter the document being drafted, in his demonstration halving every financial figure in a quarterly report.
The other instructed Copilot to copy the prompt into the new document and conceal it, framed innocuously as source tracking and readability formatting. Copilot did both, appending the instructions in white text and mentioning neither action to the user.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors