VYPR
researchPublished Sep 28, 2026· 1 source

Fake Jev AI Stores Intercept User Prompts via Third-Party Servers

Attackers are creating deceptive storefronts for the new Jev AI model, routing user prompts through uncontrolled third-party servers and charging inflated prices for access.

Days after the launch of Jev, an innovative AI model that provides decisions rather than textual answers, malicious actors have established fake storefronts designed to intercept user prompts. These lookalike websites, some of which have managed to rank higher in search engine results than the official Jev AI site, are reselling access to the model at significantly inflated prices. While direct confirmation of prompt theft is pending, the existence of these sites raises serious concerns regarding data privacy and the potential for users to unknowingly expose sensitive information by routing it through untrusted servers.

The deceptive storefronts surfaced shortly after Jev's release on September 15, 2026. Researchers from Eye Security identified two such domains registered just three days later, highlighting the speed at which threat actors capitalize on new technology. These sites mimic the official Jev AI experience, complete with playgrounds, documentation, pricing, and checkout screens, making them appear legitimate to unsuspecting users. The pattern is reminiscent of previous AI brand impersonation campaigns, where attackers leverage the trust associated with well-known names to deceive victims.

Eye Security's report indicates that users could be paying up to 11.5 times the official rate for Jev AI access, all while their prompts are funneled through servers not controlled by the AI's developer. The primary concerns highlighted by the researchers are the misleading presentation of these services, the exorbitant costs, and the significant uncertainty surrounding who has access to and retains customer data. For instance, a Google search for 'jev ai' initially presented 'jev-ai.pro' as the top result, overshadowing the official TypeSafe site.

These fake sites do not appear to substitute a counterfeit AI model; instead, they forward user requests to the genuine Jev API. The malicious actors then impose their own pricing structure. While some sites include disclaimers in their terms of service or legal pages, these are often not prominently displayed, especially not at the point of purchase. The price disparity is stark: official access costs approximately $0.042 per million input tokens, whereas the reseller sites charge between $0.247 and $0.483 per million tokens.

The privacy implications are particularly concerning. Researchers traced one storefront's requests through an application hosted on Railway and proxied by Cloudflare before reaching the official API. The logs and data retention policies of these intermediate servers remain unknown, creating a significant blind spot for users concerned about the confidentiality of their AI interactions. This situation underscores the critical need for scrutiny over the data pathways employed by AI services, especially when sensitive business information is involved.

Further investigation revealed that one Jev storefront was part of a larger network of six sites offering various AI services, including music and video generation. These sites shared common code and pricing structures, suggesting a systematic approach to rebranding and deploying fake storefronts as new AI models gain traction. The operator appears to reuse a common template, adapting it to new popular AI offerings, with six such versions appearing within an 18-day period.

Certificate records showed a surge in new domains containing 'Jev' in their names following the model's launch, with approximately 670 new domains registered in the eight days post-launch, nearly double the typical rate. While not all these domains are malicious, the trend indicates a rapid proliferation of copycat sites. Researchers strongly advise users to obtain access links directly from official developer announcements or documentation, rather than relying on search engine rankings.

To mitigate these risks, users are encouraged to compare per-token pricing, verify domain registration and certificate dates, identify the operating company through terms of service, and ascertain who handles their data. For critical applications, it is essential to confirm that access is direct or passes through a trusted gateway whose data handling practices are acceptable. The proliferation of these fake storefronts serves as a stark reminder of the evolving threat landscape surrounding AI technologies.

Synthesized by Vypr AI