Jack-in-the-box: An Empirical Study of JavaScript Bundling on the Web and its Security Implications
Jeremy Rack, Cristian-Alexandru Staicu
Abstract
In recent years, we have seen an increased interest in studying the software supply chain of user-facing applications to uncover problematic third-party dependencies. Prior work shows that web applications often rely on outdated or vulnerable third-party code. Moreover, real-world supply chain attacks show that dependencies can also be used to deliver malicious code, e.g., for carrying cryptomining operations. Nonetheless, existing measurement studies in this domain neglect an important software engineering practice: developers often merge together third-party code into a single file called bundle, which they then deliver from their own servers, making it appear as first-party code. Bundlers like Webpack or Rollup are popular open-source projects with tens of thousand of GitHub stars, suggesting that this technology is widely-used by developers. Ignoring bundling may result in underestimating the complexity of modern software supply chains. In this work, we aim to address these methodological shortcomings of prior work. To this end, we propose a novel methodology for automatically detecting bundles, and partially reverse engineer them. Using this methodology, we conduct the first large-scale empirical study of bundled code on the web and examine its security implications. We provide evidence about the high prevalence of bundles, which are contained in 40% of all websites, and the average website includes more than one bundle. Following our methodology, we reidentify 1 051 vulnerabilities originating from 33 vulnerable npm packages, included in bundled code. Among the vulnerabilities, we find 17 critical and 59 high severity ones, which might enable malicious actors to execute attacks such as arbitrary code execution. Analyzing the low-rated libraries included in bundles, we discover 10 security holding packages, which suggest that supply-chain attacks affecting bundles are not only possible, but they are already happening. CCS CONCEPTS • Security and privacy → Web application security; Software reverse engineering; • Software and its engineering → Software libraries and repositories.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5b4eec0f-ede5-4a94-b491-fd30d90cd929Cited by top-tier papers12
- Digital Disparities: A Comparative Web Measurement Study Across Economic BoundariesMasudul Hasan Masud Bhuiyan, Matteo Varvello, Cristian-Alexandru Staicu, Yasir ZakiWWW 2025 · 5 citations
- From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security AnalysisDongchao Zhou, Lingyun Ying, Huajun Chai, Dongbin WangNDSS 2026 · 3 citations
- Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript BundlesMir Masood Ali, Peter Snyder, Chris Kanich, Hamed HaddadiCCS 2024 · 2 citations
- Keys on Doormats: Exposed API Credentials on the WebNurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir DurumericCCS 2026 · 2 citations
- FP-Fed: Privacy-Preserving Federated Detection of Browser FingerprintingMeenatchi Sundaram Muthu Selva Annamalai, Igor Bilogrevic, Emiliano De CristofaroNDSS 2024
Builds on31
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky et al.S&P 2017 · 293 citations
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
Related papers
- D-BUNDLR: Destructing JavaScript Bundles for Effective Static AnalysisWenyuan Xu, Alexi Turcotte, Cristian-Alexandru StaicuICSE 2026
- Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the WebBen Swierzy, Marc Ohm, Michael MeierICSE 2026
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted LanguagesRuian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder et al.NDSS 2021
- Beyond Typosquatting: An In-depth Look at Package ConfusionShradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson et al.USENIX Security 2023
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 114 citations
