The advisory says all the versions are affected ">= 0"
Stylus has been around for 15 (FIFTEEN) years. Obviously the "vulnerability" is a lie.
Npm is known to cause huge losses of money for developers and companies around the world when they pull things like this, blindly applying advisories.