What happened
arXiv 2609.35576 (submitted 2026-09-28, in-window) formalizes 'artifact-mediated propagation' of prompt-injection state across independently operated LLM agents over time. In temporal human-agent simulations, attacks survive successive hand-offs and persist; on GPT-5.6 Luna in larger environments the payload reached 60–80% of agents with propagation chains up to eight hops. Positioned alongside the recent OpenAI self-replicating-injection disclosures as a new self-propagating attack class carried by the agent memory/artifact channel.
Why it matters
Demonstrates that an agent's persistent memory and the shared artifacts it reads/writes (reports, docs, files) can act as durable 'carrier' state for a prompt-injection worm that hops between otherwise-independent assistants and outlives individual interactions. For defenders this means artifact stores, shared drives, and agent memory backends are first-class propagation vectors: memory scanning, sandboxing of agent-written content, and treating all persisted/summary content as untrusted are required controls.
Attack vector
Adversarial content introduced through a shared artifact (e.g. a report) is stored in an assistant's persistent memory, reproduced in subsequently created artifacts, and acquired by another assistant that later reads them — propagation via artifact exchange (memory-hopping), no direct agent-to-agent communication required.
Affected systems
Stateful LLM assistants with persistent memory and tool access to shared artifacts (evaluated incl. GPT-5.6 Luna); universal across agent harnesses using artifact/persistence stores
Mitigation
Treat every persisted artifact and memory entry consumed by agents as untrusted instruction content; isolate agent memory; scan/neutralize adversarial content in shared artifacts; restrict the tools that let agents write shared, re-readable artifacts; monitor for persisted instruction-like payloads.