'Playing off the curiosity of your friends'
The code also attempts to attract new targets through social engineering on Facebook.
“Your account is also used to tag the names of all your friends in the comment section of the original post. This is done to help the scam spread further, playing off the curiosity of your friends, who may visit the post to find out more and hopefully follow the instructions as well,” explains Narang.
The scam uses a variation of what is called self cross-site scripting (self-XSS), where a user is tricked into entering code into their browser’s console window that performs certain actions on their behalf.