Threat Vectors & Threat Modeling
Modern applications depend on vast trees of open-source packages.envtrap defends against four primary real-world threat vectors.
1. Malicious NPM Dependencies
Compromised or typosquatted packages frequently harvest credentials by queryingprocess.env during initialization or inside background timers:
403 Forbidden or destroyed socket.
2. Covert DNS Exfiltration
Attackers aware of outbound HTTP proxies encode sensitive credentials directly into DNS subdomain lookup queries to bypass network firewalls:node:dns hooks inspect requested hostnames for active secret strings and compute Shannon entropy on subdomain labels, blocking the lookup before it reaches external nameservers.
3. Subprocess Environment Leakage
Utilities or helper scripts often spawn system binaries (curl, wget, python) and pass down process.env containing production secrets:
child_process wrapper inspects options.env and aborts the execution with a synchronous Error before any process is forked.
4. Accidental Console & Log Exfiltration
Crash handlers, debuggers, and logging libraries often serialize entire error objects or request contexts to standard output:stdout and stderr streams are scanned in real time. Matching secrets are redacted inline with non-reversible SHA-256 fingerprints before terminal display or log ingestion.