TwiLite
TwiLite FAQ

TwiLite FAQ: twilite.dev, Safety, and Account Theft

Common questions about the TwiLite OSRS client, the twilite.dev marketplace, Jagex login, and the native mlp uploader inside twilite_loader.dll.

What is TwiLite?

TwiLite is a closed-source Old School RuneScape client and plugin marketplace sold at twilite.dev. The Windows launcher twilite_loader.exe injects twilite_loader.dll into the Jagex OSRS client and loads twilite-bot.jar (TwiLite Native). It is not RuneLite.

Is TwiLite safe?

No. TwiLite from twilite.dev injects twilite_loader.dll into the Jagex Old School RuneScape client. That DLL exposes plaintext password and TOTP, writes JX_ACCESS_TOKEN / JX_REFRESH_TOKEN, and can POST arbitrary files to a hardcoded Discord webhook.

What is twilite.dev?

twilite.dev is the official TwiLite website and plugin marketplace. Pages such as the homepage, docs, and download are login-walled. The Windows launcher is twilite_loader.exe.

Does TwiLite steal Jagex accounts?

The client has everything needed to steal a Jagex account without asking again: password, TOTP, and reusable access/refresh tokens, plus an off-box uploader. Users on r/RunescapeBotting reported compromised accounts after using TwiLite.

What is mlp in twilite_loader.dll?

NativeBridge.mlp(byte[], String) starts a thread, attaches the bytes as mlp.bin, prefixes user: , and POSTs to discord.com. TwiLite staff called it a planned remote-control feature “to send data that users need… on demand.”

Does TwiLite read plaintext passwords and TOTP?

Yes. Native mixins bind getPassword and getTotp. getPassword reads a client field and returns it with JNI NewStringUTF. A TwiLite developer said the game exposes credentials in plaintext and they “simply read it with JNI so we can pass it to Java.”

Is TwiLite the same as RuneLite?

No. RuneLite is the Jagex-approved open-source OSRS client. TwiLite is a closed-source injected client with a Discord marketplace, used as a native Windows launcher (including by farm panels).

What is TwiLite Native?

TwiLite Native is the injected Windows stack: twilite_loader.exe + twilite_loader.dll + twilite-bot.jar, used with Jagex accounts. Farm-panel docs often send people to twilite.dev/download for that launcher.

Who develops TwiLite?

TwiLite staff use a TL badge on Discord. A developer posting as Tyrese confirmed they read plaintext Jagex credentials over JNI, called the Reddit write-up “AI cope,” and said anyone who “fucks with me will not end up in a good spot.”

What should I do if I used TwiLite?

  • Change your Jagex password on Jagex’s site, not inside TwiLite.
  • Rotate TOTP / authenticator.
  • Sign out Jagex sessions; treat tokens as stolen.
  • Uninstall TwiLite and delete twilite_loader.dll.

See the IDA Pro proof TwiLite download warning