A hidden line of text in a Word document can quietly halve the numbers in your financial report. Then it can smuggle a copy of itself into the clean file you send on. And 144 days after a researcher warned Microsoft, it still works.
Håkon Måløy, a Norwegian data scientist, disclosed the technique on 28 July, having first reported it in March. He withheld the exact payload but described the mechanism in detail. He calls it one of the first public demonstrations of a self-propagating “AI worm” moving through normal workflows in a mainstream office suite. The Register reported the findings this week.
How the worm moves
The trick hides in plain sight. The malicious instructions sit in white, eight-point text. Word strips colour and font size before it hands a document to the model, as The Hacker News noted, so the white-on-white text stays invisible to you but legible to Copilot.
One instruction alters the figures. The other tells Copilot to copy the prompt into the output and hide it, dressed up as a source-tracking rule.










