Why not? Ever since I heard of the idea of trying to replace QR codes with passive always on NFC I've thought that this will be one of the first methods for massive infections of smartphones. Just put one in a public place(public transportation, store, etc.)
Note you only have to slam a shim in; the shim can then download an arbitrary payload.
[1]: http://krebsonsecurity.com/2012/07/atm-skimmers-get-wafer-th...
The only unique theoretical option would be to hack a very highpowered antenna and transmitter to try and pick up blast out RFID-compatible signals to/from the very weak NFC radios of handsets from further away.
And attacks doesn't need to come from cots phones, with your own higher gain NFC device, you can interact with with ordinary NFC devices from greater distances.