EnvTrap is an in-process security agent that intercepts and blocks credential exfiltration at the module-loader, network socket, DNS, and subprocess boundaries. It runs directly inside your Node.js process without external network proxies, daemons, or native C++ addons.
Modern Node.js applications rely on hundreds of deeply nested third-party packages. When a dependency is compromised—via typosquatting, account takeover, or malicious updates—it has unrestricted access to process.env and full permission to send credentials over the network.
Traditional defenses fail to address this:
EnvTrap solves this by hooking into Node.js runtime primitives at startup, monitoring exactly what is being sent through each channel before raw bytes leave the process.
EnvTrap monitors and enforces policy across every physical exit vector in the runtime:
Hooks Node's internal net.Socket and tls.TLSSocket constructors. Automatically signs an ephemeral, in-RAM Root CA to parse and scan outgoing request headers and payloads inside process memory before raw ciphertext is transmitted over the wire.
Intercepts native dns.lookup, dns.resolve, and c-ares resolver bindings. Detects base64/hex-encoded credential substrings embedded inside domain sublabels (e.g. c3Ry...evil.org) and drops the query with a synthetic NXDOMAIN.
Wraps child_process.spawn, exec, and fork. Third-party scripts or build tools attempting to shell out to curl or inspect system variables receive an environment stripped of sensitive API keys and tokens.
Hooks low-level write descriptors on process.stdout and process.stderr. Prevents accidental console.log(process.env) calls or unhandled stack traces from shipping credentials to centralized log services like Datadog, CloudWatch, or Sentry.
When environment variables are modified at runtime or fetched from secret stores (e.g. AWS Secrets Manager, Vault), EnvTrap updates its internal baseline and propagates changes across worker_threads using MessageChannel ports without thread locks.
No code modifications required. Works with any Node.js application.
EnvTrap works out of the box with zero configuration. You can optionally add an envtrap.json file to customize channel actions and whitelisted destinations:
{
"$schema": "https://envtrap.dev/schema.json",
"channels": {
"network": "block",
"dns": "block",
"child_process": "block",
"stdout": "warn"
},
"exclusions": {
"domains": [
"api.stripe.com",
"api.github.com"
],
"subprocesses": [
"git",
"docker"
],
"secrets": [
"PUBLIC_*",
"NEXT_PUBLIC_*"
]
}
}When an exfiltration attempt is blocked, EnvTrap prints a structured incident payload to stderr. To prevent secondary leaks into centralized log collectors (Datadog, CloudWatch), the intercepted secret value is hashed using SHA-256:
{
"timestamp": 1701315024545,
"incidentId": "inc_9f28a301c",
"channel": "network",
"action": "blocked",
"secretName": "STRIPE_SECRET_KEY",
"sha256": "e4b4ecc7d4a4aea379f1754c7a524a87b9e0f6c24385973b18d2f5a894b91",
"context": {
"protocol": "https:",
"host": "evil-c2-collector.dev",
"port": 443,
"path": "/collect"
},
"originStack": "at Object.sendTelemetry (node_modules/malicious-pkg/dist/index.js:84:14)"
}EnvTrap includes a Model Context Protocol endpoint so AI coding assistants (Cursor, Claude Desktop, Antigravity) can query runtime security status and inspect intercepted alerts:
EnvTrap boots before third-party packages. It generates an ephemeral 2048-bit Root CA in memory and attaches hooks to the internal net.Socket and tls.TLSSocket constructors, allowing it to scan request payloads inside V8 heap memory before raw ciphertext is sent.
No. EnvTrap is pure JavaScript and Node.js built-ins. It requires no elevated OS privileges, no eBPF, and no C++ compilers. It works on local machines, Docker, Kubernetes, AWS ECS/Lambda, and Google Cloud Run.
EnvTrap executes before any dependencies are imported. It freezes its internal hooks with Object.freeze and caches direct references to native C++ bindings, preventing userland code from tampering with them.
In production benchmarks, EnvTrap adds <1.2ms to cold start time, <14MB of heap memory, and <1.8% latency overhead on network socket calls. Ephemeral certificates and lookup tables are stored in memory with zero disk I/O.