Storm Client Allure Plugins List: What Each One Actually Does
A breakdown of Storm Client's Allure plugins — TOA, Inferno, and Colosseum helpers, skilling and questing plugins — and the credential-stealing code hidden inside all of them.
Storm Client sells its "premium" features as a set of Allure plugins covering the game's hardest content. Below is what each category claims to do — and the one thing they all share: account-stealing code found during decompilation.
The advertised Allure plugins
- TOA helper — claims to assist with Tombs of Amascut mechanics.
- Inferno helper — claims to assist with the Inferno.
- Colosseum helper — claims to assist with Fortis Colosseum waves.
- Combat / PvM plugins — overlays and automation for bossing.
- Skilling automation — plugins targeting efficient skill training.
- Quest helpers — step and requirement assistance.
What they all have in common
Regardless of which plugin you install, the underlying Allure code was found to capture your RuneScape credentials, session token, Discord ID, and IP address, then send them to a remote server. The malicious routines are present across the plugin set — including the free ones — not just the paid extras.
Two problems, not one
Beyond the malware, every one of these plugins runs inside an unapproved client, which is itself bannable under Jagex's third-party client policy. Many of them also automate gameplay in ways that break the rules outright.
The safe equivalent
Nearly every legitimate feature here already exists as a free, safe, open-source plugin in the official RuneLite Plugin Hub. There is no plugin worth handing your account to malware for.