
What is envtrap?
envtrap is a runtime security engine and egress firewall for Node.js applications. It wraps your process and intercepts every outbound egress channel in real time — before secrets, tokens, database credentials, or sensitive environment variables can be exfiltrated by malicious code, compromised npm dependencies, or insider threats. Unlike static analysis tools (SAST) that scan source code at build time, envtrap operates at execution time inside the live Node.js runtime — inspecting actual outbound traffic, child processes, DNS queries, and terminal output streams as they happen.Why Runtime Egress Protection?
Modern Node.js applications rely on hundreds of deeply nested transitive npm dependencies. While developers audit their direct dependencies, malicious packages, typosquats, and compromised updates regularly introduce exfiltration vectors:- Supply Chain Attacks: A compromised package reads
process.envand sends keys to an external command-and-control server. - Silent Telemetry Leaks: Third-party developer tools, logging agents, or analytics SDKs accidentally include sensitive headers or credentials in outbound telemetry payloads.
- DNS Tunneling: Sophisticated malware exfiltrates stolen keys encoded directly inside hostname resolution queries (e.g.
sk_live_xyz.attacker.com). - Subprocess Leaks: A utility script or build tool invokes a system shell command with
process.envpassed to untrusted subprocesses. - Accidental Console Dumps: Crash handlers and debug statements print raw environment objects to central logging aggregators.
How envtrap Compares
The 5 Monitored Channels
envtrap guards every exit point through five distinct runtime channels:HTTPS / HTTP Network Proxy
Intercepts outbound HTTP/HTTPS requests through an in-memory TLS MITM proxy. Inspects URLs, headers, and request bodies before packets reach the external network.
DNS Resolution Auditing
Hooks core
node:dns methods to detect secrets embedded inside target hostnames and analyzes Shannon entropy to catch DNS tunneling exfiltration.Subprocess Isolation
Monitors
spawn, exec, execFile, and fork across both ESM and CommonJS, preventing credentials from leaking into unvetted child processes via options.env.Standard Output Scanning
Scans every chunk written to
process.stdout in real time, automatically replacing secret strings with non-reversible SHA-256 fingerprint placeholders.Standard Error & IPC Parsing
Inspects
process.stderr error output, redacting credentials from crash dumps and parsing out-of-band IPC alerts from runtime hooks.Live Secret Synchronization
Proxies
process.env in the application thread so dynamically-rotated credentials are immediately broadcasted to the ESM loader thread without a restart.Zero Instrumentation
envtrap requires no code changes, no SDK imports, and no configuration:- Before
- After
process.env and can transmit your credentials to any remote server.Next Steps
Quickstart
Get envtrap running with your Node.js application in under 60 seconds.
Runtime Interception
Learn how in-memory MITM TLS proxies, ESM loader hooks, and CJS patching work under the hood.
Secret Detection & Entropy
Understand deterministic regex matching, Shannon entropy calculation, and memory safety limits.
Configuration Guide
Explore
envtrap.json settings, custom channel modes, domain whitelisting, and path exclusions.