An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use Cases
Aaron Hilbig, Daniel Lehmann, Michael Pradel
Abstract
WebAssembly has emerged as a low-level language for the web and beyond. Despite its popularity in different domains, little is known about WebAssembly binaries that occur in the wild. This paper presents a comprehensive empirical study of 8,461 unique WebAssembly binaries gathered from a wide range of sources, including source code repositories, package managers, and live websites. We study the security properties, source languages, and use cases of the binaries and how they influence the security of the WebAssembly ecosystem. Our findings update some previously held assumptions about real-world WebAssembly and highlight problems that call for future research. For example, we show that vulnerabilities that propagate from insecure source languages potentially affect a wide range of binaries (e.g., two thirds of the binaries are compiled from memory unsafe languages, such as C and C++) and that 21% of all binaries import potentially dangerous APIs from their host environment. We also show that cryptomining, which once accounted for the majority of all WebAssembly code, has been marginalized (less than 1% of all binaries found on the web) and gives way to a diverse set of use cases. Finally, 29% of all binaries on the web are minified, calling for techniques to decompile and reverse engineer WebAssembly. Overall, our results show that WebAssembly has left its infancy and is growing up into a language that powers a diverse ecosystem, with new challenges and opportunities for security researchers and practitioners. Besides these insights, we also share the dataset underlying our study, which is 58 times larger than the largest previously reported benchmark. CCS CONCEPTS • Security and privacy → Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 948d60d3-40f4-4824-ab2d-896d692faf43Cited by top-tier papers25
- An Empirical Study of Bugs in WebAssembly CompilersAlan Romano, Xinyue Liu, Yonghwi Kwon, Weihang WangASE 2021 · 43 citations
- Wobfuscator: Obfuscating JavaScript Malware via Opportunistic Translation to WebAssemblyAlan Romano, Daniel Lehmann, Michael Pradel, Weihang WangS&P 2022 · 40 citations
- Finding the dwarf: recovering precise types from WebAssembly binariesDaniel Lehmann, Michael PradelPLDI 2022 · 29 citations
- Exploring Missed Optimizations in WebAssembly OptimizersZhibo Liu, Dongwei Xiao, Zongjie Li, Shuai Wang et al.ISSTA 2023 · 24 citations
- MSWasm: Soundly Enforcing Memory-Safe Execution of Unsafe CodeAlexandra E. Michael, Anitha Gollamudi, Jay Bosamiya, Evan Johnson et al.POPL 2023 · 22 citations
Builds on9
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 282 citations
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer et al.CCS 2018 · 162 citations
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 125 citations
Related papers
- An Empirical Study of WebAssembly Usage in Node.jsMichelle Thalakottur, Maxwell Bernstein, Daniel Lehmann, Michael Pradel et al.ICSE 2026
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
- That's a Tough Call: Studying the Challenges of Call Graph Construction for WebAssemblyDaniel Lehmann, Michelle Thalakottur, Frank Tip, Michael PradelISSTA 2023 · 11 citations
- Static Stack-Preserving Intra-Procedural Slicing of WebAssembly BinariesQuentin Stiévenart, David W. Binkley, Coen De RooverICSE 2022 · 18 citations
- Jack-in-the-box: An Empirical Study of JavaScript Bundling on the Web and its Security ImplicationsJeremy Rack, Cristian-Alexandru StaicuCCS 2023 · 11 citations
