Fake storefronts appeared days after the launch of Jev, an artificial intelligence model that returns decisions rather than written answers.
The sites offer access to the service, but they put an unrelated operator between users and the official API. That means prompts and any information inside them travel through a third-party server first.
The lookalike pages surfaced in search results for the new model, complete with playgrounds, documentation, pricing and checkout screens.
Some ranked ahead of the official site for relevant searches. The pattern echoes earlier AI brand impersonation campaigns that relied on familiar names to earn users’ trust. Researchers Dion Fieret and Lucas Hop from Eye Security identified the storefronts and traced the way they resell access.
Eye Security said in a report shared with Cyber Security News (CSN) that users could pay up to 11.5 times the official rate while sending their prompts through servers they do not control.
The report does not describe a malware infection or establish that operators stole prompts. Its immediate concerns are misleading presentation, higher costs and uncertainty over who can access or retain customer data.
This matters most when a team submits private business information while assuming it is communicating directly with the model’s developer.
Attackers Create Fake Jev AI Stores
Jev launched on September 15, 2026. Two lookalike domains were registered three days later, about 11 hours apart and through different registrars.
Eye’s researchers found that searches for the product could direct visitors to these shops instead of the developer’s website, a risk also seen in search result poisoning attacks involving AI tools.
The sites do not appear to substitute a counterfeit model. They forward requests to the genuine API, then charge their own prices for access.
One site’s terms acknowledge that it passes requests to an upstream model, but visitors would need to read carefully to understand the arrangement.
Affiliation disclaimers appear in footers or legal pages, not at checkout. The difference in price is substantial. Official access costs $0.042 per million input tokens, according to the researchers.
.webp)
Monthly plans at two reseller sites work out to $0.247 to $0.483 per million, or roughly six to 11.5 times as much. Annual billing lowers one site’s rate, but requires payment up front.
The privacy question is harder to price. Researchers traced one storefront’s requests through an app hosted on Railway behind Cloudflare before they reached the official API.
They could not tell who retained logs, and reported no service agreement covering the route. Similar concerns about AI conversation data exposure show why the path prompts take deserves scrutiny.
Shared Templates Follow Trending Models
One Jev storefront was part of a wider group of six sites that used the same code across music, video and other AI offerings. Its scripts still contained billing rules for video generation.
The researchers said the operator reused a common storefront, changing the branding when a model attracted attention. Six versions appeared within 18 days.
These sites shared monthly plans priced at $29, $49 and $98, along with welcome credits and daily rewards. A countdown for annual savings reset each day, creating a recurring sense of urgency. Some checkouts said payments were not yet available.
The team also saw legal-policy dates change during its investigation. Certificate records showed about 670 new domains containing the model’s name in the eight days after launch, roughly twice the usual background rate.
That count is not a count of malicious sites. Some related pages offered free information, while others were listed for sale or remained blank.
The overlap with fake AI tool websites nevertheless shows how quickly a new launch can attract copycats. Researchers advise getting access links from the developer’s own announcement or documentation rather than search rankings.
Buyers should compare per-token prices, check domain registration and certificate dates, identify the company named in the terms, and ask who handles their data.
For production use, verify that access is direct or passes through a gateway whose handling of prompts the organization accepts.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | jev-ai[.]pro | Jev reseller; shares code with other AI storefronts |
| Domain | jevtypesafeai[.]com | Jev reseller; routes prompts through a third-party app |
| Domain | jev-agent[.]org | Jev reseller listed by researchers |
| Domain | jev-agent[.]com | Jev reseller listed by researchers |
| Domain | jevapi[.]pro | Jev reseller listed by researchers |
| Domain | jevmodel[.]org | Jev reseller listed by researchers |
| Domain | jevai[.]site | Jev reseller listed by researchers |
| Domain | lyria35[.]pro | Other storefront using the shared code |
| Domain | h3maxturbo[.]pro | Other storefront using the shared code |
| Domain | faceless-reels[.]pro | Other storefront using the shared code |
| Domain | taomateh3[.]pro | Other storefront using the shared code |
| Domain | laya-ai[.]pro | Other storefront using the shared code |
| Domain | jevai[.]ai | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]io | Jev-related domain also reported as listed for sale |
| Domain | jevai[.]co | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]cc | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]vip | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]xyz | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]me | Jev-related domain observed in certificate records; misuse not established |
| Domain | jevapi[.]io | Jev-related registered name; misuse not established |
| Domain | jevgateway[.]com | Jev-related registered name; misuse not established |
| Domain | jevjudge[.]ai | Jev-related registered name; misuse not established |
| Domain | jevplayground[.]com | Described by researchers as a free playground, not a confirmed harmful site |
| Domain | jevultrafast[.]com | Jev-related registered name; misuse not established |
| Domain | jevsystem[.]one | Jev-related registered name; misuse not established |
| Domain | jevharnessrouter[.]com | Jev-related registered name; misuse not established |
| Domain | typesafeai[.]app | Brand-related registered name; misuse not established |
| Domain | typesafe[.]pro | Describes itself as an independent access gateway |
| Domain | typesafeapi[.]com | Brand-related registered name; misuse not established |
| Domain | typesafeintelligence[.]com | Brand-related registered name; misuse not established |
| Domain | jevai[.]co[.]uk | Jev-related domain reported as listed for sale |
| Domain | jevhub[.]com | Jev-related domain reported as listed for sale |
| Domain | typesafejev[.]com | Brand-related domain reported as listed for sale |
| Domain | jev[.]pro | Described by researchers as a field guide, not a confirmed harmful site |
| Domain | typesafe[.]ai | Official vendor domain; benign reference, not a malicious indicator |
| Domain | console[.]typesafe[.]ai | Official dashboard; benign reference, not a malicious indicator |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

