Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
@item-shop-data/clientnpm
Malicious code in @item-shop-data/client (npm) Remove it immediately and rotate any exposed credentials.
MAL-2025-49104
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @item-shop-data/client
What this malware does
The package @item-shop-data/client was found to contain malicious code.
Malicious versions
0.0.1-security56.0.056.0.356.0.1058.0.158.0.9058.90.9059.0.90
Indicators of compromise (SHA-256)
f3931756a8f0da8b385e1c2b974c51fef803ddf8c0c6cb84ed0dacf3b3e6c1bd
Frequently asked questions
No. @item-shop-data/client on npm has been identified as a malicious package (versions 0.0.1-security, 56.0.0, 56.0.3, 56.0.10, 58.0.1, 58.0.90, 58.90.90, 59.0.90 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Credits
- Amazon Inspector · finder
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection