670 Jev Domains Registered After Launch as Fake AI Marketplaces Target Users
About 670 lookalike Jev domains appeared days after launch, with fake shops marking up API access.
Eye Security found about 670 domains containing "jev" received TLS certificates within eight days of TypeSafe AI launching its Jev decision model on September 15. Operating storefronts, including jev-ai.pro, present API docs and checkout flows while proxying prompts to TypeSafe and charging roughly six to 11.5 times the official $0.042 per million input tokens. Researchers tied jev-ai.pro to at least six similarly built AI storefronts registered through Namecheap and placed behind Cloudflare. The scheme creates overpayment and prompt-data exposure risks, alongside typosquatting and possible API-key theft.
- Roughly 670 jev domains received certificates within eight days of launch.
- Fake shops proxy prompts to TypeSafe while charging up to 11.5 times list price.
- jev-ai.pro matches a cluster of similar storefronts on Namecheap and Cloudflare.
- Third-party transit can expose proprietary prompts, records, and API credentials.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | faceless-reels.pro | ociated domains included lyria35[.]pro , h3maxturbo[.]pro , faceless-reels[.]pro , taomateh3[.]pro , jev-ai[.]pro , and laya-ai[.]pro . Al |
| domain | h3maxturbo.pro | day period. The associated domains included lyria35[.]pro , h3maxturbo[.]pro , faceless-reels[.]pro , taomateh3[.]pro , jev-ai[.]pro , |
| domain | jev-agent.org | . By comparison, monthly plans promoted by jev-ai[.]pro and jev-agent[.]org equated to approximately $0.247 to $0.483 per million inp |
| domain | jev-ai.pro | n generated prose. By comparison, monthly plans promoted by jev-ai[.]pro and jev-agent[.]org equated to approximately $0.247 to $0 |
| domain | jevtypesafeai.com | but still cost three to six times more than direct access. jevtypesafeai[.]com offered starter packages that worked out to $0.25 to $0.4 |
| domain | laya-ai.pro | faceless-reels[.]pro , taomateh3[.]pro , jev-ai[.]pro , and laya-ai[.]pro . All were registered through Namecheap, deployed behind |
Full article761 words · extracted from gbhackers.com · click to collapse
A surge of lookalike domains targeting users of TypeSafe AI’s newly launched Jev decision model, with roughly 670 “jev”-branded domains obtaining TLS certificates within eight days of the product’s debut.
Several sites are already operating as unofficial API storefronts, charging customers up to 11.5 times the official rate while proxying prompts to TypeSafe’s infrastructure.
TypeSafe introduced Jev on September 15 as a “System One” model designed to return typed, structured decisions such as choices, scores, and yes/no outcomes rather than generative text.
The model is aimed at automation workloads where applications need predictable, schema-bound outputs instead of conversational responses.
The rapid interest in Jev has also created an opportunity for opportunistic domain operators.
The sites offered API documentation, playgrounds, pricing tiers, and checkout flows that could make them appear official to developers seeking immediate access.
The storefronts do not appear to offer an independent Jev implementation.
Instead, researchers said requests are forwarded to TypeSafe’s upstream API, placing an undisclosed intermediary between customers and the official platform.
This creates both a financial and a data-security concern: users may overpay while allowing prompts, potentially containing proprietary source code, customer records, or internal business data, to transit through third-party servers.

TypeSafe lists Jev input processing at $0.042 per million tokens, or $42 per billion tokens, while output is free because the model returns typed decisions rather than generated prose.
By comparison, monthly plans promoted by jev-ai[.]pro and jev-agent[.]org equated to approximately $0.247 to $0.483 per million input tokens about six to 11.5 times the official rate.
The sites used shared JavaScript, recurring subscription tiers, “50% off” annual-payment messaging, welcome credits, daily check-in rewards, and countdown timers that reset each day.
Annual plans on jev-ai[.]pro reduced the premium but still cost three to six times more than direct access.
jevtypesafeai[.]com offered starter packages that worked out to $0.25 to $0.42 per million tokens, representing a six- to ten-fold markup, according to the research.
670 Jev Domains Registered
Disclaimers stating that the services were not affiliated with TypeSafe were present, but were reportedly limited to footers or legal pages rather than prominently disclosed during purchase flows.

Eye Security found that, searches for “Jev AI” and “Jev TypeSafe” surfaced websites such as jev-ai[.]pro and jevtypesafeai[.]com above TypeSafe’s legitimate properties.
Researchers linked jev-ai[.]pro to a wider network of at least six similarly structured AI storefronts launched over an 18-day period.
The associated domains included lyria35[.]pro, h3maxturbo[.]pro, faceless-reels[.]pro, taomateh3[.]pro, jev-ai[.]pro, and laya-ai[.]pro.
All were registered through Namecheap, deployed behind Cloudflare, and contained shared site identifiers in their code, researchers said.
The pattern suggests a repeatable monetization model: identify a trending AI product, register a keyword-rich domain, clone a generic commercial interface, connect it to an upstream service, and impose a substantial markup.
Some legal pages on the Jev storefronts also contained effective dates that predated the domains’ registrations, according to the investigation.
In one case, the dates were later changed while the researchers were conducting their analysis.
Certificate Transparency logs revealed about 670 newly certified domains containing “jev” between September 15 and 22, with an estimated 170 registrations on September 18 alone the same day that the first identified clone domains were registered.
Researchers also identified approximately 40 new domains containing “typesafe” between September 16 and 21.
Not every newly registered domain is malicious or deceptive. Some are guides, demos, community projects, or inactive parked domains.
However, the growth of keyword-heavy registrations increases phishing, typosquatting, SEO poisoning, credential theft, and API-key exposure risks particularly while demand for a newly released service outpaces the availability of verified official access.
Organizations should access Jev only through TypeSafe’s official typesafe.ai and console.typesafe.ai properties, or through established providers listed by researchers, including OpenRouter, Vercel AI Gateway, and Cloudflare AI Gateway.
Security teams should verify the source of vendor links through official announcements or documentation rather than search rankings; inspect domain registration and first-seen certificate dates; compare token pricing against the vendor’s published rate.
For production workloads, an intermediary without a clear legal entity, security documentation, retention policy, or contractual SLA should be treated as a material supply-chain and data-governance risk.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.