
Serverless computing has rapidly emerged as a prominent cloud paradigm, enabling developers to focus solely on application logic without the burden of managing servers or underlying infrastructure. Public serverless repositories have become key to accelerating the development of serverless applications. However, their growing popularity makes them attractive targets for adversaries. Despite this, the security posture of these repositories remains largely unexplored, exposing developers and organizations to potential risks. In this paper, we present the first comprehensive analysis of the security landscape of serverless components hosted in public repositories. We analyse 2,758 serverless components from five widely used public repositories popular among developers and enterprises, and 125,936 Infrastructure as Code (IaC) templates across three widely used IaC frameworks. Our analysis reveals systemic vulnerabilities including outdated software packages, misuse of sensitive parameters, exploitable deployment configurations, susceptibility to typo-squatting attacks and opportunities to embed malicious behaviour within compressed serverless components. Finally, we provide practical recommendations to mitigate these threats.
Acknowledgments. We thank the anonymous reviewers for their insightful feedback and help in improving this paper. This research received funding from the Smart Networks and Services Joint Undertaking (SNS JU) under the European Union’s Horizon Europe programme: ELASTIC (GA#101139067); Horizon Europe: FLUIDOS (GA#101070473) and LAZARUS (GA#101070303); and the UNICO I+D Cloud program funded by the Ministry of Economic Affairs and Digital Transformation and the European Union–NextGenerationEU within the framework of the Plan de Recuperación, Transformación y Resiliencia (PRTR) with the CLOUDLESS project. This work was partially supported by project SERICS (PE00000014) under the NRRP MUR program funded by the EU-NGEU. Additionally, this work was partly supported by the National Research Foundation of Korea (NRF) grant funded by the Korea government (MSIT) (No. RS-2024-00457937, Design and implementation of security layers for secure WebAssembly-based serverless environments). The content of this article does not reflect the official opinion of the EU. Responsibility for the information and views expressed lies entirely with the authors.
FOS: Computer and information sciences, Cryptography and Security, serverless computing, security and privacy, Cryptography and Security (cs.CR), public repositories
FOS: Computer and information sciences, Cryptography and Security, serverless computing, security and privacy, Cryptography and Security (cs.CR), public repositories
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
