Techniques for secure package installation into a target container are described. The described techniques utilize a temporary service container to execute files for installation of a package into a target container. The service container provides an execution environment that is at least partially isolated from a host system and thus package file execution within the service container reduces vulnerability of the host system to potentially unsecure files and processes that may result from file execution.