Forum Moderators: travelin cat
The bad news: it installs keystroke logging software and disables firewalls
The good news: it's not self-propagating yet.
My understanding is that it's more of a root kit than it is a worm - it does all sorts of nasty things, but needs to be installed with root access.
This would only become a problem if a vector is discovered for remotely gaining access to an OSX machine, or if someone uses social engineering tactics (like a fake security advisory sent as spam) to trick a user into running the script themselves.
Once you have root (administator) access, you can do whatever you want, including wiping the entire hard disk.
If your network has a lot of Mac users with admin access and easy passwords, and at least one user dumb enough to install dirty software, this could be a problem.
That's a lot of ifs, but I did go ahead and change my password here at work, just in case.