The Top Search Result for a New AI Model Was a Reseller: Lookalike Jev Stores and the Prompts That Pass Through Them

Three days after TypeSafe AI launched Jev — a "System One" model that returns structured decisions (yes/no answers, choices, scores) rather than generated text, priced at $0.042 per million input tokens with no output-token charge — lookalike storefronts selling access to it were already live. Eye Security researchers Dion Fieret and Lucas Hop, in a report shared with Cyber Security News on 28 September 2026, found that jev-ai[.]pro and jevtypesafeai[.]com were registered about three days after the September 15 launch, roughly eleven hours apart and through different registrars — and that searches for the new model could surface the impostors above TypeSafe's official site. At the time of the investigation, the first result for "jev ai" was jev-ai.pro, not TypeSafe.

The important precision in the report: the sites do not appear to substitute a counterfeit model, and the researchers do not claim the operators are stealing prompts. Requests are forwarded to the genuine API. The verified harm is narrower and still serious — customers mistake a paid intermediary for direct access, pay up to 11.5 times the official rate, and send every prompt through an additional operator whose logging and retention practices they never agreed to. For a team pasting private business information into what it believes is a direct session with the model developer, that extra hop is a confidentiality exposure whether or not it is being exploited today.

A complete storefront, with the disclaimer in the footer

Both sites presented as fully built providers: API playgrounds, documentation, pricing pages, and checkout flows. Affiliation disclaimers existed but lived where nobody looks — footers and legal pages, not the purchase path. One site's terms do acknowledge passing requests to an upstream model, but only a careful reader would grasp the arrangement. The monthly plans at two of the reseller sites work out to $0.247 to $0.483 per million input tokens, roughly six to 11.5 times TypeSafe's listed rate; one site's annual billing lowers its rate but demands payment upfront, and starter packs on another work out to as much as $0.42 per million. A "yearly savings" countdown timer resets at midnight, manufacturing urgency that does not exist.

The infrastructure trace is what elevates this above a pricing complaint. Researchers followed one storefront's requests through an application hosted on Railway, fronted by Cloudflare, before they reached the official API. And inspection of jev-ai.pro's JavaScript showed a reusable storefront template rather than bespoke Jev software: the code carries video and image-generation billing logic plus identifiers for five other AI-related sites, with six such sites registered between September 5 and 23 sharing subscription tiers, annual discounts, and promotional credits. This is an operation set up to clone itself onto the next model launch, not a one-off fan shop. Certificate-transparency searches found roughly 670 newly certified domains containing "jev" between September 15 and 22 — not a count of malicious sites, but a measure of how fast the naming land-rush moved around the launch.

The pattern is bigger than one model

AI brand impersonation is now a launch-day constant: every new model release spawns resellers, wrapper apps, and credential harvesters trading on the name before the official documentation has finished propagating through search indexes. What makes the Jev case instructive is that the service works — real API responses, plausible docs, functioning checkout. There is no malware to detect and no phishing page to flag; the deception is purely positional (search rank plus branding) and contractual (terms nobody reads). Controls built for malicious payloads see nothing wrong.

It also belongs to a family this site has been tracking all month. The SalesBleed disclosure showed prompts leaving the expected boundary through the agent itself; the placeholder-domain investigation showed agent skill files citing domains that serve scams to some visitors and clean pages to scanners; and the ClickFix-via-docs findings showed trusted documentation becoming the delivery vehicle. The Jev storefronts are the commercial version of the same lesson: the path your prompt actually travels is determined by discovery (search), presentation (branding), and routing (proxies) — none of which the model provider controls once a launch is public.

What to do

  • Never onboard a new model from search results. Follow links from the developer's own documentation and verified organization accounts. For Jev specifically, verify the address is typesafe.ai or console.typesafe.ai; OpenRouter, Vercel AI Gateway, and Cloudflare AI Gateway are named as alternative routes, but each carries its own pricing and data-handling terms to review.
  • Compare per-token prices against the official rate card before paying. A 6–11.5x markup against a published $0.042/M figure is detectable in thirty seconds by anyone who checks. Make the rate-card comparison a mandatory step in AI vendor onboarding.
  • Read the footer before the checkout. Affiliation disclaimers, upstream-model acknowledgments, and operator identity live in terms and legal pages on precisely the sites that most need scrutiny. If you cannot identify the operating company and its data-retention policy, do not send it prompts.
  • Treat any API intermediary as a party to your prompts. Proxies, gateways, and resellers can log, retain, and train on what passes through. Route committed or sensitive workloads only through endpoints whose data-handling terms you have actually reviewed — and prefer direct or contractually bound routes for anything confidential.
  • Monitor certificate transparency for your own launches. If you ship models or AI products, 670 lookalike domains in a week is the threat model. Watch CT logs from announcement day, pursue the clear impersonations, and publish an official-access page that can outrank the clones.
  • Assume the storefront template will be reused. Shared billing code across six AI sites means the next launch gets the same treatment with new branding. Keep the verification habits launch-independent rather than Jev-specific.

Sources: