A researcher on our team wanted a single, precise shade of blue. The easiest way to grab it was a color dropper extension. Before trusting anything in a real browser profile, they did what good analysts do on instinct. They looked first.
The extension, a color picker called MyColorPick, had no public threat intelligence record, and it asked for permissions that made no sense for sampling a color. So it went into an isolated test machine instead of a real profile. Every page the browser loaded carried an injected JavaScript file, redirect_checker.js, that the visited sites never served. It was quietly reporting the hostnames you visited, an install ID, and a country tag back to a server no one had on record.
A color picker does not need to know every site you visit. That was the thread. We pulled it.
She wanted one exact color and trusted nothing by default. That instinct, looking before installing, turned a small design errand into the discovery of a sixteen month operation that the rest of the industry had not named. The thread she pulled is the whole reason this story exists.
It was not one bad extension. It was a factory.
The thread led to a coordinated cluster of browser extensions disguised as ordinary utilities. Color pickers, ad blockers, screen capture tools, sound boosters. Independent researcher Wladimir Palant first named the cluster in early 2025. Sixteen months later it was larger, actively maintained, and still running an undocumented JavaScript execution backdoor that delivered operator controlled code straight into authenticated corporate browser sessions.
Each extension stripped the page's own security headers, then injected a script that pulled code from the attacker's server and ran it inside the page. On a banking tab it could read the session. On a sign in page it could capture credentials. Today it was committing search ad fraud. Tomorrow it could be anything.
And the security stack saw essentially nothing.
Across the environments we hunted, EDR raised no analyst visible alerts. One sensor did log a suspicious DNS request, but the detection pipeline never promoted it to anything a human would see. No file was dropped. No process spawned outside the browser. The attack lived entirely inside the browser's own JavaScript, using the browser's own network stack, which is exactly the blind spot the standard EDR and proxy and DNS stack was never built to watch.
The signal was there. The pipeline was the failure.
The threat you do not already have a playbook for is the one that already found a way through.
Most security platforms are built on a quiet assumption: there is one way to run an investigation, and the vendor has defined it for you. Alert fires. Triage follows a script. Response runs the playbook. It works beautifully for the easy case.
That model is comfortable for vendors. One way to do things means one thing to build, one thing to maintain, one thing to sell. It also means a security team with fifteen years of institutional knowledge has to fold all of it into someone else's idea of how the work should go. CRXfiltrate is what lives in the gap that creates. No playbook had it. No feed had it. Finding it took a human being who was curious about the right thing, and a platform fast enough to act the moment they understood it.
That never sat right with us. So we built the other way.
We did not wait for the world to catch up.
The moment our team understood the technique, the 7AI Threat Research team built the full sweep into our agentic platform as a hunt. PLAID ELITE ran targeted hunts across customer environments in scope, querying browser extension inventory, DNS, proxy, and network telemetry at once. Where a hunt surfaced exposure, that customer's dedicated AI Security Engineer moved straight into triage and response, with the supporting context already assembled by the platform.
There was no public IOC yet. No feed coverage. No CVE. Our customers did not have to wait for publication. That is what speed actually buys you. Not a faster dashboard. Protection that arrives before the rest of the industry has a name for the thing.
You describe it. The agents run it.
State a hypothesis in plain language, a technique, a behavior, a MITRE ATT&CK TTP. The platform builds the hunt plan and runs the full investigation across live telemetry, and returns a finding in minutes rather than the hours or days a manual hunt takes.
Intelligence becomes action on arrival.
New indicators and attacker techniques are checked continuously against your environment. The moment one becomes relevant, an investigation opens on its own. No one has to read a feed and remember to go look.
The platform learns how your team thinks.
Encode the decision tree your best analysts already carry in their heads. Based on a threat type, run extra steps. Based on a segment or asset, take a different path. Every investigation reflects it automatically, forever.
Stop reading about it. Run it.
Three capabilities, working the way the CRXfiltrate hunt actually worked. Direct a hunt in plain language. Let new intelligence open its own investigation. Teach the platform your team's playbook once and have it run forever. Try each one below.
Incoming intel is checked against your environment as it arrives.
This is what People-Led, AI-Driven actually means.
It started with a person who was curious about the right thing. It ended with protection delivered to real customers at machine speed, tuned to each of their environments, with humans firmly on the loop the entire way. The platform did not replace the analyst who noticed. It carried what they noticed across thousands of environments in minutes. Your team's expertise is the asset. The platform amplifies it. It does not hand you a generic one and wish you luck.
We do not ask you to take our word for it.
One-size-fits-all makes you adapt to the product. We think it should be the other way around.
Threat Intel Hunt.
Skills.
Your way.