30+ developer ecosystems
Developer Cache Cleaner for npm, Homebrew, Gradle and More
Worm Cleaner is a developer cache cleaner for macOS that covers more than thirty package ecosystems. It finds npm, pnpm, Yarn, Homebrew, Gradle, pip, uv, Poetry, Composer, RubyGems, Cargo-adjacent build caches, Terraform, kubectl and Electron leftovers, reports the size of each, and only deletes what you tick.
By Naman Namdev
Clepsydra Technologies
Updated
Version 1.0.4
General-purpose cleaners treat ~/.npm and ~/.gradle as one undifferentiated blob, if they see them at all. That is why developers keep hitting a full disk: the caches that matter are the ones nobody surfaces individually. Worm's scan catalog enumerates them as separate labelled targets, each with a real size.
What it cleans, by ecosystem
What Worm Cleaner removes on macOS| Category | What gets cleaned |
| Xcode and Swift | DerivedData, Xcode build products, the Xcode cache, Simulator cache, XCTest device data, SwiftPM cache |
| JavaScript | npm, tnpm, Yarn (classic and v2), Corepack, node-gyp, Electron |
| Package managers | Homebrew downloads, Gradle build cache and daemon logs, pip, uv, Poetry, pypoetry, pytest, mypy, ruff, Jupyter, PyInstaller |
| Other languages | RubyGems, Bundler, rbenv, Composer, CPAN, Hex, opam, pre-commit |
| Browsers | Chrome, Edge, Brave, Firefox, Opera, Comet, Arc, Vivaldi, Helium, Yandex, Kagi and Dia — application and profile caches |
| Editors and CLI | VS Code, Cursor, Terraform plugins, kubectl, AWS CLI |
| App leftovers | Orphaned bundle identifiers, preference plists and Application Support folders left by uninstalled apps |
| Monitoring | Menu bar CPU, memory (App / Wired / Compressed), disk and thermal readouts |
Is it safe to clear these caches?
Package-manager caches are re-downloadable, which makes them safe in the technical sense but not free: clearing npm costs you a re-download of every dependency, and on a metered or slow connection that is a real cost. This is why Worm separates them into the Safe and Re-download tiers and shows the badge, so you can clear the free wins without paying for the downloads.
Every target carries one of four risk tiers, and the tier decides what is ticked by default:
- Safe — rebuilt automatically by the app. Deleting costs only time.
- Re-download — fetched again from the network. Anything expired in there is gone for good.
- Keep — your content, not a cache. Off by default, and needs an explicit per-item opt-in.
- Blocked — system-owned or not rebuildable. Never offered as a target at all.
How Worm compares to the native commands
The native tools are good and Worm does not replace them — it complements them. npm cache clean --force clears npm's cache in one shot but reports nothing before or after. brew cleanup prunes old versions and downloads. gradle --stop and a manual rm -rf ~/.gradle/caches are the common approaches. What none of them do is tell you, across all ecosystems at once, which caches are large enough to be worth the rebuild cost.
Worm's contribution is the inventory: one scan, every cache measured, then you decide which native commands are worth running.
How to clean developer caches safely
- Close your editors and build tools. Targets in use are flagged by a liveness probe rather than deleted underneath a running process.
- Run a scan. Developer Tools is the relevant category; expand it to see every labelled cache with its size.
- Start with the Safe tier — regenerable caches cost only time.
- Treat the Re-download tier as a deliberate choice. If you are on a slow connection, leave them.
- Clean, then check
~/Library/Logs/Worm/deletions.tsv to see exactly what went.
Docker, WSL and virtualisation caches
On Windows, Worm cleans the Docker Desktop builder cache and dangling image layers, alongside WSL, Hyper-V and BlueStacks targets. On macOS, Docker is reported read-only rather than cleaned — image layers and container state are easy to misjudge, so the scan surfaces them for you to inspect without offering them as deletion targets.
Frequently asked questions
Can I delete the npm cache?
Yes. The npm cache in ~/.npm/_cacache holds downloaded tarballs, not your projects or node_modules. Deleting it is safe and costs a re-download of dependencies on your next install. Use `npm cache clean --force` if you want npm's own tooling, or clear it in Worm if you would rather see its size first and clear it alongside your other caches.
Is it safe to clear the Homebrew cache?
Yes. Homebrew's downloads folder holds installer files it has already used. Clearing it is safe — Homebrew re-downloads anything it needs again. The `brew cleanup` command also prunes old installed versions and stale downloads; Worm clears the downloads cache as part of a scan so you can see its size alongside everything else.
What is the safest developer cache to clear first?
Anything in the Safe tier, which is regenerable rather than re-downloadable. Xcode DerivedData, the Gradle build cache, npm logs and cache directories are the usual large wins. Hold off on package tarball caches such as npm _cacache or Homebrew downloads if your connection is slow, since clearing those means re-downloading.
Does cleaning caches break my projects?
No. Caches are disposable by definition, and Worm never targets source repositories, git history, project files or node_modules. The realistic cost is a slower next build or install. Run Simulation-style review first — every target is listed with its path and size before anything is deleted, and running processes are flagged rather than cleaned through.
How do I free space for development?
Scan with the Developer Tools category expanded and sort by size. The largest caches are almost always the ones you have forgotten about: a Gradle build cache from a project you stopped working on, npm tarballs from a package you stopped using, or Xcode DerivedData from a client project that ended months ago.
Download Worm Cleaner
Worm Cleaner is free, MIT licensed and runs on macOS 14+ and Windows 10/11. No account, no subscription, no telemetry in the app.