Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers
Eye Security found fake Jev AI storefronts reselling genuine API access while routing user prompts through attacker-controlled third-party servers at up to 11.5x official prices.
Researchers Dion Fieret and Lucas Hop at Eye Security identified lookalike storefronts registered three days after Jev's September 15, 2026 launch, with jev-ai[.]pro ranking first in Google results for the model. The sites forward requests to the genuine API but charge $0.247-$0.483 per million input tokens versus the official $0.042, with one routing prompts through a Railway app behind Cloudflare and no data handling agreement. One storefront belonged to a six-site group sharing code across music, video, and AI offerings, rebranded as new models gained attention. No malware or confirmed prompt theft was established; concerns center on misleading presentation, data exposure risk, and overcharging.