Macs are definitely more secure than PCs, but they can still be compromised. Exploits like this are especially dangerous since you can't remove it even if you wipe and reinstall OSX! At the very least, Mac users should be using some type of realtime antimalware package to protect against malicious downloads.

New exploit leaves most Macs vulnerable to permanent backdooring
Hack allows firmware to be rewritten right after older Macs awake from sleep.