The software project itself is probably fine, but the legal risk is always going to be with the person that hosts it with the intention of facilitating the unauthorized access of Twitter's website. Seems like that could run afoul of the Computer Fraud and Abuse Act.
Those people should seek their own legal advice.
Host the infra in countries unfriendly to the US and its legal framework apparatus. Continually package the archive as torrents for distribution globally.
Except this is settled case law. LinkedIn tried and lost against scrapers.
The project maintainer, Zedeus, runs the most or second-most popular instance, and I assume his lawyers decided that was okay.