A cross-site scripting worm has been detected at Twitter by F-Secure. A message with a username called Mikeyy posts on the website. If a user views an already infected profile, his or her profile will be infected as well. The location, bio, website, and name information will be changed to Mikeyy and the infected users will start to post messages such as “Twitter, you should be paying me now. – mikeyy” and “@cnnbrk – he’s back. ;) – mikeyy”.

The blog entry at F-Secure include two screen shots of the messages. It also includes a list of messages that the worm uses.

Source: F-Secure