Iron Software A.I CyberSecurity Scoring
Iron Software
Company Information
Website:http://www.ironsoftware.com
Employees number:52
Number of followers:5,020
NAICS:5112
Industry Type:Software Development
Homepage:ironsoftware.com
Iron Software Risk Score (AI oriented)
Between 700 and 749
Iron SoftwareSoftware Development
Updated:
07/05/2026
07/05/2026
737/1000
Moderate
Ba
Iron Software Global Score (TPRM)
xxxx
Iron SoftwareSoftware Development
Score locked

Iron SoftwareModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
739
AUGUST 2026
739
JULY 2026
738
JUNE 2026
738
MAY 2026
737
APRIL 2026
737
MARCH 2026
736
FEBRUARY 2026
736
JANUARY 2026
735
DECEMBER 2025
735
NOVEMBER 2025
734
OCTOBER 2025
734
SEPTEMBER 2025
751
Cyber Attack
01 Sep 2025 • Iron Software
NuGet: Malicious NuGet Packages Steal Browser Credentials, SSH Keys, and Crypto Wallets
Malicious NuGet Packages Target .NET Developers, Stealing Credentials and Crypto Data
732
CRITICAL-19
IRO1778142529
Malicious NuGet Packages Target .NET Developers, Stealing Credentials and Crypto Data
A sophisticated campaign is leveraging malicious NuGet packages to steal browser credentials, SSH keys, and cryptocurrency wallet data from developer machines and CI/CD infrastructure, with a focus on Chinese .NET ecosystems. The attack, identified by Socket’s Threat Research Team, involves five packages IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, and IR.iplus32 published under the account bmrxntfj.
These packages mimic legitimate Chinese WinForms and enterprise libraries, embedding a heavily obfuscated .NET Reactor-protected infostealer. Since late 2025, the packages have accumulated 65,000 downloads across 224 versions, with 219 deliberately hidden to evade detection. The attacker maintains only one visible version at a time, rotating unlisted builds to inflate install counts while avoiding hash-based scans.
Execution begins upon loading any IR. assembly, triggering a multi-stage infection process. The malware verifies an RSA-1024 anti-tamper signature, allocates read-write-execute memory, and hooks clrjit.dll!getJit to inject attacker-controlled code during JIT compilation. Cross-platform support ensures functionality on Windows, Linux, and macOS*, with obfuscated API calls to evade static analysis.
The infostealer targets 12 Chromium-based browsers (including Chrome, Edge, and Brave), Firefox, and Thunderbird, extracting passwords and session cookies via IElevator COM interface exploitation. It also harvests cryptocurrency wallet data from MetaMask, TronLink, Phantom, Trust Wallet, and Coinbase Wallet, along with files from Exodus, Electrum, and Ledger. Additional targets include SSH keys, Outlook profiles, Steam sessions, and documents from Desktop, Documents, and Downloads directories.
Stolen data is staged at C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltration to https://dns-providersa2[.]com/upload, using randomized X-{3 lowercase letters} headers to bypass network signatures. The C2 domain, registered in March 2026, resolves to a VDSINA VPS in Amsterdam and is shielded by privacy-focused registrar Njalla.
Attribution links the packages to a unique .NET Reactor RSA public key, connecting them to additional artifacts like s4.exe and fake CRYPT32.DLL.MUI binaries. While YARA rules associate the samples with families like Lumma, Quantum, and AgentRacoon, the exact threat actor remains unclear. A private Alibaba Cloud-hosted Git server (git[.]justdotrip[.]com) is believed to host the operator’s development environment.
Any system that restored or loaded these packages since September 2025 should be considered compromised. With 65,000 downloads, the campaign’s impact spans developer workstations and CI/CD pipelines, exposing sensitive data to theft. Defenders are advised to scan for the five package IDs, rotate exposed credentials, and block traffic to the identified C2 infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Iron Software ??
What was Iron Software's A.I Rankiteo Cyber Score in August 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in July 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in June 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in May 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in April 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in March 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in February 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in January 2026 ??
What was Iron Software's A.I Rankiteo Cyber Score in December 2025 ??
What was Iron Software's A.I Rankiteo Cyber Score in November 2025 ??
What was Iron Software's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Iron Software's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Iron Software ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Iron Software's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?