Skip to content
@EnvTrap

EnvTrap

Runtime secret leak prevention for Node.js

EnvTrap

Runtime secret leak prevention for Node.js applications.

EnvTrap is an open-source, in-process security runtime agent that intercepts and blocks credential exfiltration across module-loaders, network sockets, DNS queries, and subprocesses before raw bytes leave your machine.


What EnvTrap Does

Modern software stacks rely on hundreds of third-party npm dependencies. A single compromised dependency can harvest process.env secrets and transmit them externally. EnvTrap injects hooks at startup to monitor and enforce policy across 5 physical egress channels:

  1. Network Egress (TLS & Raw Sockets): Intercepts net.Socket and tls.TLSSocket payloads in V8 heap memory before raw ciphertext reaches the physical network interface.
  2. DNS Tunneling Defense: Hooks native dns and c-ares resolver calls to detect encoded secret strings embedded inside domain sublabels.
  3. Subprocess Environment Isolation: Sanitizes inherited environment variables passed to child_process.spawn, exec, and fork.
  4. Stdout & Stderr Redaction: Hooks process output descriptors to prevent accidental print statements or crash dumps from leaking API keys into centralized log managers.
  5. Dynamic Secret Sync: Propagates runtime secret rotations across worker_threads using internal MessageChannel ports without thread locks.

Quickstart

Run your application with zero configuration or code modifications:

# Direct run via npx
npx envtrap run node app.js

# Or install globally
npm install -g envtrap
envtrap run node app.js

Pinned Loading

  1. docs docs Public

    Docs

    MDX

  2. envtrap-website envtrap-website Public

    website for EnvTrap

    TypeScript

  3. envtrap-package envtrap-package Public

    Zero-dependency secret leak prevention for Node.js.

    JavaScript 1

Repositories

Showing 4 of 4 repositories

Top languages

Loading…

Most used topics

Loading…