If anyone is still interested in how the worm works, I found a great explanation,with code, here:
Hacking Entrepreneurship: Reverse engineering the latest Facebook worm
It's actually quite simple and brilliant: they put the code FB inserts to prevent this in a textarea tag so it doesn't run.
Thx for the link, reading it now.
Crazy shit.