Subprocess Channel (child_process)
- Default Mode:
"warn" - Target:
node:child_processAPI invocations across ESM and CommonJS.
child_process channel monitors subprocess invocations to ensure that malicious dependencies or utility scripts do not pass sensitive environment variables to system binaries (curl, wget, bash, python).
Intercepted APIs
envtrap wraps the following Node.js subprocess methods:
child_process.spawn&spawnSyncchild_process.exec&execSyncchild_process.execFile&execFileSyncchild_process.fork
Detection Logic
When an application invokes an intercepted method:envtrapinspects the environment passed to the child process. Ifoptions.envis explicitly provided, it inspects that object. Ifoptions.envis undefined (the default in Node.js subprocesses),envtrapevaluates the calling process’sprocess.envsince the child process inherits it by default.- For each key in the inspected environment, it checks whether the key exists in the active secret registry and the assigned value matches the secret value.
- If a match is found, an alert or block is triggered before the operating system process is spawned.
- Asynchronous and synchronous method signatures—including
(error, stdout, stderr)callback handlers onchild_process.execandchild_process.execFile—are strictly preserved with standard error objects and exit status parity.
Enforcement Modes
- warn (Default)
- block
- off
Writes an alert to
stderr, logs the incident in .envtrap-report.json, and allows the subprocess to execute with inherited options.Configuration Example
envtrap.json
