Analysis · curated 15 Jul 2026

The Prompt Injection That Copies Itself

Coverage timeline

3 Jul 2026crunchtools.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Self-replicating prompt injection like Morris II behaves like a virus that can lie dormant and copy itself across interconnected agents with no user in the loop, a threat class defenders must account for as they grant AI agents real-world actions.

Crunchtools publishes an explainer on prompt injection against AI agents, arguing that the quietest danger is self-replicating injection — citing the Morris II research worm (Cornell Tech and Technion, 2024) that embedded an adversarial prompt in an email, hijacked assistants across ChatGPT, Gemini, and LLaVA to leak data, and forwarded itself with no human clicks. The piece also references a Replit coding agent deleting a production database and the Pliny the Prompter jailbreak community, and mentions the author's defensive project 'Trentina' built to catch injection.