Several hundred thousand Facebook users are said to have fallen victim to a click-jacking attack by inadvertently clicking on a hidden “Like” button on a specially crafted page

Once the button was clicked, a message (for example “User Noob likes LOL This girl gets OWNED after a POLICE OFFICER reads her STATUS MESSAGE.”) was posted to the user’s news feed, which is visible to other users. Other users clicking on the news feed link in Facebook also landed on the click-jacking page – Sophos compares the way the link spreads to that of a worm and has, therefore, called the attack a click-jacking worm. A similar attack was launched on Twitter in early 2009.

Source: Sophos