Runtime secret leak prevention for Node.js applications.
EnvTrap is an open-source, in-process security runtime agent that intercepts and blocks credential exfiltration across module-loaders, network sockets, DNS queries, and subprocesses before raw bytes leave your machine.
Modern software stacks rely on hundreds of third-party npm dependencies. A single compromised dependency can harvest process.env secrets and transmit them externally. EnvTrap injects hooks at startup to monitor and enforce policy across 5 physical egress channels:
- Network Egress (TLS & Raw Sockets): Intercepts
net.Socketandtls.TLSSocketpayloads in V8 heap memory before raw ciphertext reaches the physical network interface. - DNS Tunneling Defense: Hooks native
dnsandc-aresresolver calls to detect encoded secret strings embedded inside domain sublabels. - Subprocess Environment Isolation: Sanitizes inherited environment variables passed to
child_process.spawn,exec, andfork. - Stdout & Stderr Redaction: Hooks process output descriptors to prevent accidental print statements or crash dumps from leaking API keys into centralized log managers.
- Dynamic Secret Sync: Propagates runtime secret rotations across
worker_threadsusing internalMessageChannelports without thread locks.
Run your application with zero configuration or code modifications:
# Direct run via npx
npx envtrap run node app.js
# Or install globally
npm install -g envtrap
envtrap run node app.js