
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
htcachemon is a tool to view statistics about entries in an Apache `mod_disk_cache` cache. Users can also manually purge URLs from the cache. It uses the Apache `htcacheclean` tool in the back-end to accomplish this.
htcachemon is a tool to view statistics about entries in an Apache
mod_disk_cache cache. Users can also manually purge URLs from the cache.
It uses the Apache htcacheclean tool in the back-end to accomplish this.

Both the server component and the web interface should be secured from unauthorised access. Exactly what measures you take to achieve that is left as an exercise for the reader.
You will need to have node.js and the Apache htcacheclean utility
installed and, of course, an Apache server and a mod_cache_disk cache.
cd into your cloned repository and run npm install to install the NPM
packages that the server component depends on.<repo>/config.js to suit your system. Common items to change will
be cacheDir, uid and http.port.uid in the config.js
file. The serve.sh script provides an example of this.The web interface is just a set of static files to create an AngularJS single page application. All dependencies are provided (or come from CDNs).
<repo>/ui/config.js to suit your system. You will
likely need to change the API endpoint.<repo>/ui.If you are only testing, you can use the devserve.sh script to serve
the web interface. You will need to have http-server installed - for example,
via npm -g install http-server.
FAQs
htcachemon is a tool to view statistics about entries in an Apache `mod_disk_cache` cache. Users can also manually purge URLs from the cache. It uses the Apache `htcacheclean` tool in the back-end to accomplish this.
We found that htcachemon demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.