Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Fake storefronts appeared days after the launch of Jev, an artificial intelligence model that returns decisions rather than written answers.

The sites offer access to the service, but they put an unrelated operator between users and the official API. That means prompts and any information inside them travel through a third-party server first.

The lookalike pages surfaced in search results for the new model, complete with playgrounds, documentation, pricing and checkout screens.

Some ranked ahead of the official site for relevant searches. The pattern echoes earlier AI brand impersonation campaigns that relied on familiar names to earn users’ trust. Researchers Dion Fieret and Lucas Hop from Eye Security identified the storefronts and traced the way they resell access.

Eye Security said in a report shared with Cyber Security News (CSN) that users could pay up to 11.5 times the official rate while sending their prompts through servers they do not control.

The report does not describe a malware infection or establish that operators stole prompts. Its immediate concerns are misleading presentation, higher costs and uncertainty over who can access or retain customer data.

Google search for ‘jev ai’ – the first result is jev-ai.pro, not TypeSafe (Source – Eye)

This matters most when a team submits private business information while assuming it is communicating directly with the model’s developer.

Attackers Create Fake Jev AI Stores

Jev launched on September 15, 2026. Two lookalike domains were registered three days later, about 11 hours apart and through different registrars.

Eye’s researchers found that searches for the product could direct visitors to these shops instead of the developer’s website, a risk also seen in search result poisoning attacks involving AI tools.

The sites do not appear to substitute a counterfeit model. They forward requests to the genuine API, then charge their own prices for access.

One site’s terms acknowledge that it passes requests to an upstream model, but visitors would need to read carefully to understand the arrangement.

Affiliation disclaimers appear in footers or legal pages, not at checkout. The difference in price is substantial. Official access costs $0.042 per million input tokens, according to the researchers.

Price list of jev-ai.pro (Source - Eye)
Price list of jev-ai.pro (Source – Eye)

Monthly plans at two reseller sites work out to $0.247 to $0.483 per million, or roughly six to 11.5 times as much. Annual billing lowers one site’s rate, but requires payment up front.

The privacy question is harder to price. Researchers traced one storefront’s requests through an app hosted on Railway behind Cloudflare before they reached the official API.

They could not tell who retained logs, and reported no service agreement covering the route. Similar concerns about AI conversation data exposure show why the path prompts take deserves scrutiny.

One Jev storefront was part of a wider group of six sites that used the same code across music, video and other AI offerings. Its scripts still contained billing rules for video generation.

The researchers said the operator reused a common storefront, changing the branding when a model attracted attention. Six versions appeared within 18 days.

These sites shared monthly plans priced at $29, $49 and $98, along with welcome credits and daily rewards. A countdown for annual savings reset each day, creating a recurring sense of urgency. Some checkouts said payments were not yet available.

The team also saw legal-policy dates change during its investigation. Certificate records showed about 670 new domains containing the model’s name in the eight days after launch, roughly twice the usual background rate.

That count is not a count of malicious sites. Some related pages offered free information, while others were listed for sale or remained blank.

The overlap with fake AI tool websites nevertheless shows how quickly a new launch can attract copycats. Researchers advise getting access links from the developer’s own announcement or documentation rather than search rankings.

Buyers should compare per-token prices, check domain registration and certificate dates, identify the company named in the terms, and ask who handles their data.

For production use, verify that access is direct or passes through a gateway whose handling of prompts the organization accepts.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain jev-ai[.]pro Jev reseller; shares code with other AI storefronts
Domain jevtypesafeai[.]com Jev reseller; routes prompts through a third-party app
Domain jev-agent[.]org Jev reseller listed by researchers
Domain jev-agent[.]com Jev reseller listed by researchers
Domain jevapi[.]pro Jev reseller listed by researchers
Domain jevmodel[.]org Jev reseller listed by researchers
Domain jevai[.]site Jev reseller listed by researchers
Domain lyria35[.]pro Other storefront using the shared code
Domain h3maxturbo[.]pro Other storefront using the shared code
Domain faceless-reels[.]pro Other storefront using the shared code
Domain taomateh3[.]pro Other storefront using the shared code
Domain laya-ai[.]pro Other storefront using the shared code
Domain jevai[.]ai Jev-related domain observed in certificate records; misuse not established
Domain jevai[.]io Jev-related domain also reported as listed for sale
Domain jevai[.]co Jev-related domain observed in certificate records; misuse not established
Domain jevai[.]cc Jev-related domain observed in certificate records; misuse not established
Domain jevai[.]vip Jev-related domain observed in certificate records; misuse not established
Domain jevai[.]xyz Jev-related domain observed in certificate records; misuse not established
Domain jevai[.]me Jev-related domain observed in certificate records; misuse not established
Domain jevapi[.]io Jev-related registered name; misuse not established
Domain jevgateway[.]com Jev-related registered name; misuse not established
Domain jevjudge[.]ai Jev-related registered name; misuse not established
Domain jevplayground[.]com Described by researchers as a free playground, not a confirmed harmful site
Domain jevultrafast[.]com Jev-related registered name; misuse not established
Domain jevsystem[.]one Jev-related registered name; misuse not established
Domain jevharnessrouter[.]com Jev-related registered name; misuse not established
Domain typesafeai[.]app Brand-related registered name; misuse not established
Domain typesafe[.]pro Describes itself as an independent access gateway
Domain typesafeapi[.]com Brand-related registered name; misuse not established
Domain typesafeintelligence[.]com Brand-related registered name; misuse not established
Domain jevai[.]co[.]uk Jev-related domain reported as listed for sale
Domain jevhub[.]com Jev-related domain reported as listed for sale
Domain typesafejev[.]com Brand-related domain reported as listed for sale
Domain jev[.]pro Described by researchers as a field guide, not a confirmed harmful site
Domain typesafe[.]ai Official vendor domain; benign reference, not a malicious indicator
Domain console[.]typesafe[.]ai Official dashboard; benign reference, not a malicious indicator

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers appeared first on Cyber Security News.