Stylus package was removed by npm for malicious code
envgap__vitejs__vite-20461
Original GitHub issue ↗Opened 2025-07-23
01 / FAILURE SIGNATURE
As reported upstream
ERR_PNPM_FETCH_404 GET https://registry.npmjs.org/stylus/-/stylus-0.62.0.tgz: Not Found - 404
Not a benchmark task.
- No curated issue-specific recipe or verified environment fix is available.
02 / ENVIRONMENT RECIPE
- Base commit
Not freshly verified- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
vitejs/vite #20461 · read the original issue
### Describe the bug Vite has a peer dependency on stylus which prevents pnpm install in the proejcts ### Reproduction https://www.npmjs.com/package/stylus?activeTab=readme ### Steps to reproduce pnpm install ### System Info ```shell System ``` ### Used Package Manager pnpm ### Logs ❯ pnpm install ─╯ Scope: all 16 workspace projects Lockfile is up to date, resolution step is skipped Packages: +2920 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ERR_PNPM_FETCH_404 GET https://registry.npmjs.org/stylus/-/stylus-0.62.0.tgz: Not Found - 404 ### Validations - [x] Follow our [Code of Conduct](https://github.com/vitejs/vite/blob/main/CODE_OF_CONDUCT.md) - [x] Read the [Contributing Guidelines](https://github.com/vitejs/vite/blob/main/CONTRIBUTING.md). - [x] Read the [docs](https://vite.dev/guide). - [x] Check that there isn't [already an issue](https://github.com/vitejs/vite/issues) that reports the same bug to avoid creating a duplicate. - [x] Make sure this is a Vite issue and not a framework-specific issue. For example, if it's a Vue SFC related bug, it should likely be reported to [vuejs/core](https://github.com/vuejs/core) instead. - [x] Check that this is a concrete bug. For Q&A open a [GitHub Discussion](https://github.com/vitejs/vite/discussions) or join our [Discord Chat Server](https://chat.vite.dev/). - [x] The provided reproduction is a [minimal reproducible example](https://stackoverflow.com/help/minimal-reproducible-example) of the bug.
04 / LABELS
Labels from the report text only; not yet run
securityLabel rules and the text that matched
[
{
"category": "security",
"rule": "issue.security_keyword",
"source": "issue_title",
"excerpt": "Stylus package was removed by npm for malicious code"
}
]Transient Stylus removal reported in issue; current registry returns this package/version. Do not invent a current removed flag.
Legacy reproduction is generic install-only; match the actual issue failure before admission.