That really sucks, but I assure you, this has to be coincidence.
I understand you'll hate me and you won't use Iwana from now on, but please believe me, Iwana has nothing to do with this.
Proof (technical):
One way to obtain the password you send would be through a packet sniffer. WoW encodes your password as well, which would make it much harder.
Autoit does not contain any such functionality, which would require external .dll's compiled in a variant of C (C#, C++ etc) or possibly another language, but Iwana comes with no .dlls, neither does it install any.
Another option would be a keylogger, but my question then would be:
Did both you and your friend start Iwana AFTER or BEFORE you logged in?
If one of you started Iwana after logging in, that will prove that Iwana does not contain a keylogger
Note to everybody, Iwana is 100% clean, I absolutely promise. It sucks that these things happen, but if just 2 out of 5.000 users have these issues, what are the odds that I really did build such functionality? Wouldn't I have "hacked" more accounts?
btw: Thanks Hefty for answering some questions 