UPDATE: it appears one of the dev accounts associated with Stylus published a *different* malicious package; stylus does not appear to have been compromised. The stylus team is updating the community via their project GitHub page, and working with NPM to restore service for the package.