Back to Newsroom
Threat Intel

Fake "Jev AI" Storefronts Are Hijacking Prompts Through Hidden Third-Party Relays

Days after a new AI model's launch, researchers found lookalike storefronts charging up to 11x list price while quietly routing customer prompts through unaccountable third-party servers.

Fake "Jev AI" Storefronts Are Hijacking Prompts Through Hidden Third-Party Relays

Fake "Jev AI" Storefronts Are Hijacking Prompts Through Hidden Third-Party Relays

When a promising new AI model launches, attackers are often faster to market than the legitimate ecosystem around it. Security researchers have documented exactly that pattern following the recent launch of an AI model referred to as "Jev": within hours of the official release, look-alike storefronts began appearing — some registered mere hours apart, through different domain registrars, a pattern that points to coordination rather than opportunism.

What happened

The counterfeit sites don't run a fake or degraded model. Instead, they proxy real requests to the legitimate API while charging customers anywhere from six to more than eleven times the official per-token price. One storefront routed traffic through a third-party application hosted behind a generic cloud proxy before it ever reached the genuine API — a hop that made it impossible for researchers to determine who could see, log, or retain the prompts passing through it.

Some of these sites do technically disclose, in footer text or a legal page, that they resell access to an upstream model rather than operate their own. But the disclosure is easy to miss, and the surrounding design — convincing branding, countdown timers on "discounted" annual plans, daily login rewards — is built to create urgency rather than clarity.

Investigators also traced the same underlying storefront template across a wider network of sites selling access to unrelated AI image, video, and audio tools — the same billing logic, the same interface, simply re-skinned with a new brand each time a fresh product gains attention. Six different brand variants of the template appeared in just over two weeks. In the eight days following the Jev launch, certificate-transparency logs showed roughly 670 new domains referencing the model's name — about twice the typical background rate for a launch of this size. Most of those domains are not confirmed malicious; many are parked, listed for sale, or unrelated pages that simply mention the brand.

Why it matters

The direct financial overcharge is the least of it. Because these storefronts sit as an undisclosed relay between the user and the real API, any prompt submitted through them — proprietary code, internal business data, confidential documents — passes through infrastructure with no stated retention policy, no accountable operator, and no way for the customer to verify what happens to that data downstream. For a business user who assumes they're talking directly to a vetted AI vendor, that's a silent expansion of their data's exposure with zero visibility into who's actually receiving it.

This also illustrates a broader pattern worth internalizing: search rankings and paid ads are not proof of legitimacy for a brand-new product, and a launch's first days are precisely when copycat infrastructure is cheapest and fastest to stand up.

What to do

  • Get access links only from the vendor's own announcement or documentation — not from a search engine result, an ad, or a link shared in a chat group, especially in the first days after a launch.
  • Treat unusually low or "discounted" pricing on a brand-new AI product as a red flag, not a deal — verify the per-token rate against the vendor's published pricing before entering payment details.
  • Check domain age and certificate issuance date before trusting an AI product's website; a domain registered days after a product's announcement is a strong signal it isn't official.
  • Read footer and legal-page disclosures carefully — a site that admits it's a reseller or unofficial gateway is telling you exactly what you need to know, if you look.
  • Never submit sensitive prompts, code, or business data to a storefront or API endpoint you haven't independently verified belongs to the vendor.

If your organization is evaluating a newly launched AI model or tool, 4tify recommends validating the vendor domain, TLS certificate, and API endpoint through official channels before any credentials or sensitive data are entered.

SHARE
4Tify — Fake Jev AI Stores Hijack Prompts via Hidden Relays