Community
January 22, 20246 min read

What Reddit and the OSRS Community Say About Storm Client

A summary of what r/2007scape and the wider OSRS community say about Storm Client — the malware reports, the account-theft threads, and why the consensus is to avoid it.

Searching for the community's take on Storm Client? Across r/2007scape and OSRS forums, the sentiment is consistent: avoid it. Below is a summary of the recurring themes — and the underlying evidence that backs them up.

Recurring themes in community threads

  • Account theft reports — users describing missing items, drained banks, and unauthorized trades after installing Storm Client or Allure plugins.
  • Suspicious logins — reports of foreign IP logins shortly after use.
  • "It's not approved" — regular reminders that Storm Client isn't a Jagex-approved client and is therefore bannable.
  • Developer reputation — references to the Allure developer being banned from marketplaces like Sythe.

Why the community is right

These aren't just rumors. Decompiling the Allure plugins reveals explicit credential- and session-token-theft code that exfiltrates data to a remote server. The community's warnings line up exactly with what the code does.

The consensus recommendation

Use RuneLite through the official Jagex Launcher. It's the approved, safe, free option, and it's what experienced players consistently recommend over any paid third-party client.

Protect Your Account

If you've used Storm Client or Allure plugins, your account may be compromised. Take action now.