Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Iron Software

Iron Software Vendor Cyber Rating & Cyber Score

ironsoftware.com

Iron Software produces suite of software libraries for C# / .NET engineers working with PDFs, OCR, Excel, QR & barcodes, and data scraping. Trusted by single developers, start-ups, and engineers at NASA, Tesla, the US State Department, and more. With over 20 million downloads on NuGet in 95+ countries, Iron Software is an international company with its headquarters in Chicago, USA and an Asia base in Chiang Mai, Thailand. We take pride in our commitment to our products and engineers, offering support that covers global time zones most hours of the day via live chat and email ticket support. We’re a growing team always looking for new talent. Whether you have a love for .NET component builds, rigorous QA testing, or YouTube tutorial


Iron Software A.I CyberSecurity Scoring

Iron Software
Company Information
Website:http://www.ironsoftware.com
Employees number:52
Number of followers:5,020
NAICS:5112
Industry Type:Software Development
Homepage:ironsoftware.com
Iron Software Risk Score (AI oriented)
Between 700 and 749
logo
Iron SoftwareSoftware Development
Updated:
07/05/2026
737/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Iron Software Global Score (TPRM)
xxxx
logo
Iron SoftwareSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Iron SoftwareModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
739Before Incident
AUGUST 2026
739Before Incident
JULY 2026
738Before Incident
JUNE 2026
738Before Incident
MAY 2026
737Before Incident
APRIL 2026
737Before Incident
MARCH 2026
736Before Incident
FEBRUARY 2026
736Before Incident
JANUARY 2026
735Before Incident
DECEMBER 2025
735Before Incident
NOVEMBER 2025
734Before Incident
OCTOBER 2025
734Before Incident
SEPTEMBER 2025
751Before Incident
Cyber Attack
01 Sep 2025Iron Software
NuGet: Malicious NuGet Packages Steal Browser Credentials, SSH Keys, and Crypto Wallets

Malicious NuGet Packages Target .NET Developers, Stealing Credentials and Crypto Data

732After Incident
CRITICAL-19
IRO1778142529
Malicious NuGet Packages Target .NET Developers, Stealing Credentials and Crypto Data A sophisticated campaign is leveraging malicious NuGet packages to steal browser credentials, SSH keys, and cryptocurrency wallet data from developer machines and CI/CD infrastructure, with a focus on Chinese .NET ecosystems. The attack, identified by Socket’s Threat Research Team, involves five packages IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, and IR.iplus32 published under the account bmrxntfj. These packages mimic legitimate Chinese WinForms and enterprise libraries, embedding a heavily obfuscated .NET Reactor-protected infostealer. Since late 2025, the packages have accumulated 65,000 downloads across 224 versions, with 219 deliberately hidden to evade detection. The attacker maintains only one visible version at a time, rotating unlisted builds to inflate install counts while avoiding hash-based scans. Execution begins upon loading any IR. assembly, triggering a multi-stage infection process. The malware verifies an RSA-1024 anti-tamper signature, allocates read-write-execute memory, and hooks clrjit.dll!getJit to inject attacker-controlled code during JIT compilation. Cross-platform support ensures functionality on Windows, Linux, and macOS*, with obfuscated API calls to evade static analysis. The infostealer targets 12 Chromium-based browsers (including Chrome, Edge, and Brave), Firefox, and Thunderbird, extracting passwords and session cookies via IElevator COM interface exploitation. It also harvests cryptocurrency wallet data from MetaMask, TronLink, Phantom, Trust Wallet, and Coinbase Wallet, along with files from Exodus, Electrum, and Ledger. Additional targets include SSH keys, Outlook profiles, Steam sessions, and documents from Desktop, Documents, and Downloads directories. Stolen data is staged at C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltration to https://dns-providersa2[.]com/upload, using randomized X-{3 lowercase letters} headers to bypass network signatures. The C2 domain, registered in March 2026, resolves to a VDSINA VPS in Amsterdam and is shielded by privacy-focused registrar Njalla. Attribution links the packages to a unique .NET Reactor RSA public key, connecting them to additional artifacts like s4.exe and fake CRYPT32.DLL.MUI binaries. While YARA rules associate the samples with families like Lumma, Quantum, and AgentRacoon, the exact threat actor remains unclear. A private Alibaba Cloud-hosted Git server (git[.]justdotrip[.]com) is believed to host the operator’s development environment. Any system that restored or loaded these packages since September 2025 should be considered compromised. With 65,000 downloads, the campaign’s impact spans developer workstations and CI/CD pipelines, exposing sensitive data to theft. Defenders are advised to scan for the five package IDs, rotate exposed credentials, and block traffic to the identified C2 infrastructure.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Data Theft (Credentials, SSH Keys, Cryptocurrency Wallet Data)
IMPACT
Data Compromised: Browser credentials, SSH keys, cryptocurrency wallet data, Outlook profiles, Steam sessions, documents from Desktop/Documents/Downloads directoriesSystems Affected: Developer workstations, CI/CD pipelinesOperational Impact: Compromised development and deployment environmentsIdentity Theft Risk: High (PII, credentials, and wallet data exposed)Payment Information Risk: High (Cryptocurrency wallet data exposed)
DATA BREACH
Browser credentialsSSH keysCryptocurrency wallet dataOutlook profilesSteam sessionsDocumentsSensitivity Of Data: High (PII, financial data, authentication credentials)Data Encryption: Data staged at C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltrationPassword databasesSession cookiesWallet filesSSH keysDocuments

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Iron Software ?
?
What was Iron Software's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Iron Software's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Iron Software's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Iron Software ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Iron Software's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?