# Risky Bulletin: Damaging worm rips through npm ecosystem Page: https://stenobird.com/podcast/risky-bulletin-5423259/risky-bulletin-damaging-worm-rips-through-npm-ecosystem Text version: https://stenobird.com/podcast/risky-bulletin-5423259/risky-bulletin-damaging-worm-rips-through-npm-ecosystem.md Podcast: [Risky Bulletin](https://stenobird.com/podcast/risky-bulletin-5423259) Published: 2026-05-13T05:39:54+00:00 Episode link: https://risky.biz/RBNEWS563/ Audio file: https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWS563.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/risky-bulletin-5423259/episodes/risky-bulletin-damaging-worm-rips-through-npm-ecosystem Duration seconds: 469 ## Resource RubyGems disables sign-ups after an attack on staff, Instructure paid the ransom, the Gentlemen ransomware operation gets hacked, and another major supply chain attack on npm (yawn). ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/risky-bulletin-5423259/episodes/risky-bulletin-damaging-worm-rips-through-npm-ecosystem/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/risky-bulletin-5423259/risky-bulletin-damaging-worm-rips-through-npm-ecosystem.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.