Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers
Eye Security found fake Jev AI storefronts reselling genuine API access while routing user prompts through attacker-controlled third-party servers at up to 11.5x official prices.
Researchers Dion Fieret and Lucas Hop at Eye Security identified lookalike storefronts registered three days after Jev's September 15, 2026 launch, with jev-ai[.]pro ranking first in Google results for the model. The sites forward requests to the genuine API but charge $0.247-$0.483 per million input tokens versus the official $0.042, with one routing prompts through a Railway app behind Cloudflare and no data handling agreement. One storefront belonged to a six-site group sharing code across music, video, and AI offerings, rebranded as new models gained attention. No malware or confirmed prompt theft was established; concerns center on misleading presentation, data exposure risk, and overcharging.
- Fake Jev storefronts resell genuine API access at 6-11.5x official pricing
- Prompts pass through third-party servers with unknown logging and no data agreement
- Lookalike domains appeared within three days of Jev's September 15 launch
- jev-ai.pro outranked the official site in Google search results
- Shared storefront code spans six sites across music, video, and AI offerings
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | console.typesafe.ai | domain; benign reference, not a malicious indicator Domain console[.]typesafe[.]ai Official dashboard; benign reference, not a malicious i |
| domain | faceless-reels.pro | axturbo[.]pro Other storefront using the shared code Domain faceless-reels[.]pro Other storefront using the shared code Domain taomateh3[. |
| domain | h3maxturbo.pro | lyria35[.]pro Other storefront using the shared code Domain h3maxturbo[.]pro Other storefront using the shared code Domain faceless-re |
| domain | jev-agent.com | n jev-agent[.]org Jev reseller listed by researchers Domain jev-agent[.]com Jev reseller listed by researchers Domain jevapi[.]pro Je |
| domain | jev-agent.org | v reseller; routes prompts through a third-party app Domain jev-agent[.]org Jev reseller listed by researchers Domain jev-agent[.]com |
| domain | jevai.ai | laya-ai[.]pro Other storefront using the shared code Domain jevai[.]ai Jev-related domain observed in certificate records; misus |
Full article1,110 words · extracted from cybersecuritynews.com · click to collapse
Fake storefronts appeared days after the launch of Jev, an artificial intelligence model that returns decisions rather than written answers.
The sites offer access to the service, but they put an unrelated operator between users and the official API. That means prompts and any information inside them travel through a third-party server first.
The lookalike pages surfaced in search results for the new model, complete with playgrounds, documentation, pricing and checkout screens.
Some ranked ahead of the official site for relevant searches. The pattern echoes earlier AI brand impersonation campaigns that relied on familiar names to earn users’ trust. Researchers Dion Fieret and Lucas Hop from Eye Security identified the storefronts and traced the way they resell access.
Eye Security said in a report shared with Cyber Security News (CSN) that users could pay up to 11.5 times the official rate while sending their prompts through servers they do not control.
The report does not describe a malware infection or establish that operators stole prompts. Its immediate concerns are misleading presentation, higher costs and uncertainty over who can access or retain customer data.
.webp)
This matters most when a team submits private business information while assuming it is communicating directly with the model’s developer.
Attackers Create Fake Jev AI Stores
Jev launched on September 15, 2026. Two lookalike domains were registered three days later, about 11 hours apart and through different registrars.
Eye’s researchers found that searches for the product could direct visitors to these shops instead of the developer’s website, a risk also seen in search result poisoning attacks involving AI tools.
The sites do not appear to substitute a counterfeit model. They forward requests to the genuine API, then charge their own prices for access.
One site’s terms acknowledge that it passes requests to an upstream model, but visitors would need to read carefully to understand the arrangement.
Affiliation disclaimers appear in footers or legal pages, not at checkout. The difference in price is substantial. Official access costs $0.042 per million input tokens, according to the researchers.
.webp)
Monthly plans at two reseller sites work out to $0.247 to $0.483 per million, or roughly six to 11.5 times as much. Annual billing lowers one site’s rate, but requires payment up front.
The privacy question is harder to price. Researchers traced one storefront’s requests through an app hosted on Railway behind Cloudflare before they reached the official API.
They could not tell who retained logs, and reported no service agreement covering the route. Similar concerns about AI conversation data exposure show why the path prompts take deserves scrutiny.
One Jev storefront was part of a wider group of six sites that used the same code across music, video and other AI offerings. Its scripts still contained billing rules for video generation.
The researchers said the operator reused a common storefront, changing the branding when a model attracted attention. Six versions appeared within 18 days.
These sites shared monthly plans priced at $29, $49 and $98, along with welcome credits and daily rewards. A countdown for annual savings reset each day, creating a recurring sense of urgency. Some checkouts said payments were not yet available.
The team also saw legal-policy dates change during its investigation. Certificate records showed about 670 new domains containing the model’s name in the eight days after launch, roughly twice the usual background rate.
That count is not a count of malicious sites. Some related pages offered free information, while others were listed for sale or remained blank.
The overlap with fake AI tool websites nevertheless shows how quickly a new launch can attract copycats. Researchers advise getting access links from the developer’s own announcement or documentation rather than search rankings.
Buyers should compare per-token prices, check domain registration and certificate dates, identify the company named in the terms, and ask who handles their data.
For production use, verify that access is direct or passes through a gateway whose handling of prompts the organization accepts.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | jev-ai[.]pro | Jev reseller; shares code with other AI storefronts |
| Domain | jevtypesafeai[.]com | Jev reseller; routes prompts through a third-party app |
| Domain | jev-agent[.]org | Jev reseller listed by researchers |
| Domain | jev-agent[.]com | Jev reseller listed by researchers |
| Domain | jevapi[.]pro | Jev reseller listed by researchers |
| Domain | jevmodel[.]org | Jev reseller listed by researchers |
| Domain | jevai[.]site | Jev reseller listed by researchers |
| Domain | lyria35[.]pro | Other storefront using the shared code |
| Domain | h3maxturbo[.]pro | Other storefront using the shared code |
| Domain | faceless-reels[.]pro | Other storefront using the shared code |
| Domain | taomateh3[.]pro | Other storefront using the shared code |
| Domain | laya-ai[.]pro | Other storefront using the shared code |
| Domain | jevai[.]ai | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]io | Jev-related domain also reported as listed for sale |
| Domain | jevai[.]co | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]cc | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]vip | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]xyz | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]me | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevapi[.]io | Jev-related registered name; misuse not established |
| Domain | jevgateway[.]com | Jev-related registered name; misuse not established |
| Domain | jevjudge[.]ai | Jev-related registered name; misuse not established |
| Domain | jevplayground[.]com | Described by researchers as a free playground, not a confirmed harmful site |
| Domain | jevultrafast[.]com | Jev-related registered name; misuse not established |
| Domain | jevsystem[.]one | Jev-related registered name; misuse not established |
| Domain | jevharnessrouter[.]com | Jev-related registered name; misuse not established |
| Domain | typesafeai[.]app | Brand-related registered name; misuse not established |
| Domain | typesafe[.]pro | Describes itself as an independent access gateway |
| Domain | typesafeapi[.]com | Brand-related registered name; misuse not established |
| Domain | typesafeintelligence[.]com | Brand-related registered name; misuse not established |
| Domain | jevai[.]co[.]uk | Jev-related domain reported as listed for sale |
| Domain | jevhub[.]com | Jev-related domain reported as listed for sale |
| Domain | typesafejev[.]com | Brand-related domain reported as listed for sale |
| Domain | jev[.]pro | Described by researchers as a field guide, not a confirmed harmful site |
| Domain | typesafe[.]ai | Official vendor domain; benign reference, not a malicious indicator |
| Domain | console[.]typesafe[.]ai | Official dashboard; benign reference, not a malicious indicator |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.