The cloud environment where the code runs might be ephemeral, but it would most likely have access to some not so ephemeral resources that should still be protected.
If one wants to go sandboxing, the right place for it would be in npm, where packages should not be able to modify anything but themselves.