
#threatreport #LowCompleteness Rise of the Jev-Clones | 25-09-2026 Source: https://research.eye.security/rise-of-the-jev-clones/ Key details below ↓ 🎯Victims: Typesafe ai, Artificial intelligence users 🔓CVEs: CVE-2026-75754 \[[Vulners](https://vulners.com/cve/CVE-2026-75754)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2026-60137 \[[Vulners](https://vulners.com/cve/CVE-2026-60137)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True Soft: - wordpress (<6.8.6, <6.9.5, <7.0.2) CVE-2026-63030 \[[Vulners](https://vulners.com/cve/CVE-2026-63030)] - CVSS V3.1: *Unknown*, - Vulners: Exploitation: Unknown CVE-2026-30612 \[[Vulners](https://vulners.com/cve/CVE-2026-30612)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown 🤖LLM extracted TTPs:` T1090, T1583.001, T1583.006, T1656 🧨IOCs: - Domain: 12 💽Software: Vercel, Cloudflare, Kling, Claude 📜Programming Languages: javascript #threatreport: Three days after TypeSafe AI launched its Jev model, multiple lookalike storefronts began selling access to TypeSafe’s API at prices ranging from three to 11.5 times the official rate. The sites use TypeSafe branding and titles such as “Jev by TypeSafe AI,” while placing “not affiliated” disclaimers only in footers or legal pages. At least one site, http://jevtypesafeai.com, falsely promotes capabilities such as “0 hallucinations by construction” and “0 type errors” for a model it does not own or operate. The storefronts act as intermediaries between customers and TypeSafe. User prompts and associated data are routed through third-party infrastructure before reaching the legitimate API. For http://jevtypesafeai.com, the service reportedly runs as an application on Railway behind Cloudflare. The sites do not identify data-retention practices and provide no clear contract or service-level agreement, creating potential privacy and supply-chain risks for users submitting sensitive prompts. At least six storefronts share the same underlying codebase. Analysis of http://jev-ai.pro’s JavaScript revealed billing and model logic originally designed for video and image-generation services, including per-second video pricing, 720p and 1080p multipliers, and references to Seedance, Hailuo, Kling, Nano Banana, and Flux. The cloned sites use identical pricing tiers, welcome credits, daily check-in incentives, annual-discount messaging, and countdown timers that reset daily. All six domains were registered through Namecheap and use Cloudflare. Some payment pages indicated that payments were not yet open while payment accounts were being verified. Legal-page dates also appeared to predate domain registration and were later changed. Certificate Transparency data showed approximately 670 newly issued certificates for domains containing “jev” during 15–22 September, roughly twice the normal background rate, with a peak of about 170 registrations on 18 September. Additional domains used TypeSafe-related terms, including http://typesafeai.app, http://typesafe.pro, http://typesafeapi.com, and http://typesafeintelligence.com. Many domains were parked or blank, while others were listed for sale, indicating possible future use in impersonation or unauthorized access services.
