Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@item-shop-data/clientnpm

Malicious code in @item-shop-data/client (npm) Remove it immediately and rotate any exposed credentials.

MAL-2025-49104
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @item-shop-data/client

What this malware does

The package @item-shop-data/client was found to contain malicious code.

Malicious versions

8 flagged
0.0.1-security56.0.056.0.356.0.1058.0.158.0.9058.90.9059.0.90

Indicators of compromise (SHA-256)

f3931756a8f0da8b385e1c2b974c51fef803ddf8c0c6cb84ed0dacf3b3e6c1bd

Frequently asked questions

No. @item-shop-data/client on npm has been identified as a malicious package (versions 0.0.1-security, 56.0.0, 56.0.3, 56.0.10, 58.0.1, 58.0.90, 58.90.90, 59.0.90 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Credits

  • Amazon Inspector · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
@item-shop-data/client (npm) malicious package — MAL-2025-49104 | O3 Security