Removing the entire package is pretty unusual, normally it's only specific compromised versions.
Stylus has been around for 15 (FIFTEEN) years. Obviously the "vulnerability" is a lie.
Npm is known to cause huge losses of money for developers and companies around the world when they pull things like this, blindly applying advisories.