The company may be interested in whether they want to grant access to the user to access to their systems. Does the user shoulder any responsibility?
It shouldn't matter what malware is on a client device as long as the client has authenticated; the server/company/ebay should be protecting their API from abuse at the API layer, not the client layer.
Know your network.