Lookalike websites began reselling TypeSafe AI's Jev API shortly after the model launched on September 15, placing their own infrastructure between customers and the legitimate service. Some fraudulent or unaffiliated storefronts ranked above TypeSafe in search results and presented themselves deceptively, creating a risk that customer prompts and embedded proprietary business data could transit unverified third-party servers before reaching the official API.
Eye Security linked jev-ai.pro to at least five other rapidly deployed AI-model storefronts using shared code, hosting, pricing patterns, and embedded identifiers; another assessment described a network of six similarly rebranded sites. The resellers charged roughly three to 11.5 times TypeSafe's official input-token pricing, with reports citing approximately six to 11.5 times in some cases. No evidence established prompt theft or malware delivery, but the operators' unclear data-retention practices and undisclosed intermediary role create material confidentiality and supply-chain risks; organizations should use official TypeSafe domains or established API gateways.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Legal pages on jev-ai.pro initially showed effective dates that preceded the domain’s registration, then were reportedly changed to September 23 during the investigation.
TypeSafe AI temporarily paused new Jev registrations, citing high demand, while existing accounts continued to work.
The domain jevapi.pro was registered and reportedly resold Jev access through OpenRouter.
The domains jev-ai.pro and jevtypesafeai.com were registered three days after Jev launched. Both were later identified as reseller storefronts that forwarded requests to the official API through third-party infrastructure.
TypeSafe AI launched Jev, a typed-decision model that returns outputs such as decisions, choices, or scores. Its stated direct price was $0.042 per million input tokens, with output tokens free.
Certificate-transparency records showed about 670 newly certificated domains containing “jev” from September 15 through 22, including roughly 170 on September 18; researchers also recorded about 40 new “typesafe” domains from September 16 through 21. The reported volume did not establish that all registered domains were malicious.
CODEFASHION TECH LTD, later named by jevtypesafeai.com as its operator and billing-statement name, was incorporated at 71-75 Shelton Street in Covent Garden.
Eye Security found that Jev reseller storefronts forwarded prompts to the genuine Jev API through operator-controlled infrastructure, including a Railway-hosted application protected by Cloudflare, leaving prompt-retention terms unclear. Researchers linked jev-ai.pro to a reusable storefront framework used by other AI-themed sites and identified additional Jev resellers, while noting that prompt theft and malware delivery were not established.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceresearch.eye.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.