Skip to main content
envtrap logo

What is envtrap?

envtrap is a runtime security engine and egress firewall for Node.js applications. It wraps your process and intercepts every outbound egress channel in real time — before secrets, tokens, database credentials, or sensitive environment variables can be exfiltrated by malicious code, compromised npm dependencies, or insider threats. Unlike static analysis tools (SAST) that scan source code at build time, envtrap operates at execution time inside the live Node.js runtime — inspecting actual outbound traffic, child processes, DNS queries, and terminal output streams as they happen.

Why Runtime Egress Protection?

Modern Node.js applications rely on hundreds of deeply nested transitive npm dependencies. While developers audit their direct dependencies, malicious packages, typosquats, and compromised updates regularly introduce exfiltration vectors:
  • Supply Chain Attacks: A compromised package reads process.env and sends keys to an external command-and-control server.
  • Silent Telemetry Leaks: Third-party developer tools, logging agents, or analytics SDKs accidentally include sensitive headers or credentials in outbound telemetry payloads.
  • DNS Tunneling: Sophisticated malware exfiltrates stolen keys encoded directly inside hostname resolution queries (e.g. sk_live_xyz.attacker.com).
  • Subprocess Leaks: A utility script or build tool invokes a system shell command with process.env passed to untrusted subprocesses.
  • Accidental Console Dumps: Crash handlers and debug statements print raw environment objects to central logging aggregators.

How envtrap Compares


The 5 Monitored Channels

envtrap guards every exit point through five distinct runtime channels:

HTTPS / HTTP Network Proxy

Intercepts outbound HTTP/HTTPS requests through an in-memory TLS MITM proxy. Inspects URLs, headers, and request bodies before packets reach the external network.

DNS Resolution Auditing

Hooks core node:dns methods to detect secrets embedded inside target hostnames and analyzes Shannon entropy to catch DNS tunneling exfiltration.

Subprocess Isolation

Monitors spawn, exec, execFile, and fork across both ESM and CommonJS, preventing credentials from leaking into unvetted child processes via options.env.

Standard Output Scanning

Scans every chunk written to process.stdout in real time, automatically replacing secret strings with non-reversible SHA-256 fingerprint placeholders.

Standard Error & IPC Parsing

Inspects process.stderr error output, redacting credentials from crash dumps and parsing out-of-band IPC alerts from runtime hooks.

Live Secret Synchronization

Proxies process.env in the application thread so dynamically-rotated credentials are immediately broadcasted to the ESM loader thread without a restart.

Zero Instrumentation

envtrap requires no code changes, no SDK imports, and no configuration:
Your process runs unprotected. Any package in your dependency tree has unrestricted read access to process.env and can transmit your credentials to any remote server.
envtrap automatically sets NO_PROXY for local loopback addresses (127.0.0.1, localhost, ::1). Local Redis, Docker containers, databases, and sidecars will never experience proxy overhead.

Next Steps

Quickstart

Get envtrap running with your Node.js application in under 60 seconds.

Runtime Interception

Learn how in-memory MITM TLS proxies, ESM loader hooks, and CJS patching work under the hood.

Secret Detection & Entropy

Understand deterministic regex matching, Shannon entropy calculation, and memory safety limits.

Configuration Guide

Explore envtrap.json settings, custom channel modes, domain whitelisting, and path exclusions.