Hey everyone!
I just hit a new milestone: I’ve finally released the first version of Pompelmi, an open-source ClamAV wrapper built specifically for Node.js.
The Problem:
While working on a recent project, I needed a reliable way to scan file uploads for viruses. Most existing Node.js wrappers for ClamAV felt either abandoned, overly complex, or lacked proper Promise/Async-Await support.
The Solution:
I decided to build Pompelmi. It’s designed to be:
Simple: Minimalistic API that gets the job done without boilerplate.
Modern: Fully asynchronous and written with modern Node.js standards.
Lightweight: No heavy dependencies, just a clean bridge to your ClamAV daemon.
It’s still in its early stages, so I’d love to get some feedback from the community. If you're dealing with file security or malware scanning in your backend, I’d appreciate it if you could take a look!
Tech stack: Node.js, ClamAV.
repo: https://github.com/pompelmi/pompelmi
Looking forward to hearing your thoughts or answering any questions about the implementation!
Setting up a reliable virus scan for file uploads usually ends up being a nightmare when the available libraries are outdated or full of messy callbacks. It is a real headache for developers to deal with heavy dependencies just to bridge a simple connection to a ClamAV daemon. Since you have focused on a minimalistic async-await approach, does Pompelmi support scanning large streams directly to avoid memory spikes during heavy uploads?
Yes, Pompelmi supports direct stream scanning to prevent memory spikes.
It avoids loading entire files into RAM by piping
ReadableStreamsdirectly to the scanning engine. This allows you to process large uploads efficiently using a cleanasync/awaitsyntax without the overhead of heavy, callback-heavy libraries.Piping
ReadableStreamsdirectly to the scanning engine is the most efficient way to handle high-traffic backends because it ensures that even multi-gigabyte uploads won't crash the server's memory.Focusing on a modern async/await bridge solves a major pain point for developers who are tired of wrapping legacy callback libraries in custom promises just to keep their codebase clean.
I apply this same focus on technical efficiency and streamlined authority in high-tier PR and media placement where we highlight a product's performance to build trust on major news platforms.
Since you've optimized for large streams, does Pompelmi also include a "timeout" configuration for the daemon connection to prevent a single massive or corrupted file from hanging a worker process indefinitely?