Download KoboldCpp only from legitimate sources. The recommended is the official GitHub releases: github.com/LostRuins/koboldcpp/releases/latest.
Other download sites
Section titled “Other download sites”The official downloads are on GitHub. Files from any other site are not official and may contain malware. If you got KoboldCpp somewhere else, don't run that file; download it again from the official releases.
Official sources
Section titled “Official sources”| What | Where |
|---|---|
| Project | github.com/LostRuins/koboldcpp |
| Downloads | Latest release |
| Experimental builds | rolling and rocm-rolling tags on GitHub |
| Colab notebook | colab.research.google.com/github/LostRuins/koboldcpp/…/colab.ipynb |
| Docker image | hub.docker.com/r/koboldai/koboldcpp |
| Android setup script | raw.githubusercontent.com/LostRuins/koboldcpp/concedo/android_install.sh |
| Short links | koboldai.org, for example koboldai.org/cpplinuxrocm, koboldai.org/colabcpp, koboldai.org/runpodcpp, koboldai.org/discord |
| Official resources | Official links and mirrors |
This site links to these sources for every download and hosts no files itself.
Why antivirus may flag KoboldCpp
Section titled “Why antivirus may flag KoboldCpp”Some antivirus programs report KoboldCpp's Windows exe as a trojan or "suspicious". For a file from the official releases, this is a false positive:
- The exe is a self-extracting bundle that unpacks libraries into a temporary folder when it starts, which heuristic and machine-learning scanners can flag.
- The files are not code-signed. The maintainers don't buy signing certificates.
What to do:
- Check that the file came from the official releases, for example by comparing its checksum.
- Add it to your antivirus exceptions, and report the false positive to your antivirus vendor.
- If the file was quarantined or damaged, download it again.
On Windows, SmartScreen can show "Windows protected your PC"; see Windows. On macOS, Gatekeeper blocks unsigned files until you allow them; see macOS.
Check a downloaded file
Section titled “Check a downloaded file”The release page shows a SHA-256 checksum (sha256:…) next to each file. In a terminal, in the folder with your file, compute its checksum (use your file name) and compare the two:
| System | Command |
|---|---|
| Windows (PowerShell) | Get-FileHash koboldcpp.exe |
| Linux | sha256sum koboldcpp-linux-x64 |
| macOS | shasum -a 256 koboldcpp-mac-arm64 |
Letter case doesn't matter. If the checksums differ, the file is damaged or not the official one; delete it and download it again from the official releases.