Skip to content
KoboldCpp
GitHub

Staying safe: where to download

Download KoboldCpp only from legitimate sources. The recommended is the official GitHub releases: github.com/LostRuins/koboldcpp/releases/latest.

The official downloads are on GitHub. Files from any other site are not official and may contain malware. If you got KoboldCpp somewhere else, don't run that file; download it again from the official releases.

WhatWhere
Projectgithub.com/LostRuins/koboldcpp
DownloadsLatest release
Experimental buildsrolling and rocm-rolling tags on GitHub
Colab notebookcolab.research.google.com/github/LostRuins/koboldcpp/…/colab.ipynb
Docker imagehub.docker.com/r/koboldai/koboldcpp
Android setup scriptraw.githubusercontent.com/LostRuins/koboldcpp/concedo/android_install.sh
Short linkskoboldai.org, for example koboldai.org/cpplinuxrocm, koboldai.org/colabcpp, koboldai.org/runpodcpp, koboldai.org/discord
Official resourcesOfficial links and mirrors

This site links to these sources for every download and hosts no files itself.

Some antivirus programs report KoboldCpp's Windows exe as a trojan or "suspicious". For a file from the official releases, this is a false positive:

  • The exe is a self-extracting bundle that unpacks libraries into a temporary folder when it starts, which heuristic and machine-learning scanners can flag.
  • The files are not code-signed. The maintainers don't buy signing certificates.

What to do:

  1. Check that the file came from the official releases, for example by comparing its checksum.
  2. Add it to your antivirus exceptions, and report the false positive to your antivirus vendor.
  3. If the file was quarantined or damaged, download it again.

On Windows, SmartScreen can show "Windows protected your PC"; see Windows. On macOS, Gatekeeper blocks unsigned files until you allow them; see macOS.

The release page shows a SHA-256 checksum (sha256:…) next to each file. In a terminal, in the folder with your file, compute its checksum (use your file name) and compare the two:

SystemCommand
Windows (PowerShell)Get-FileHash koboldcpp.exe
Linuxsha256sum koboldcpp-linux-x64
macOSshasum -a 256 koboldcpp-mac-arm64

Letter case doesn't matter. If the checksums differ, the file is damaged or not the official one; delete it and download it again from the official releases.