> Following legal advice
It's impossible to know what this "legal advice" was, but the software project itself is probably fine. The legal risk is always going to be with the person that hosts it with the intention of facilitating the unauthorized access of Twitter's website. Seems like that could run afoul of the Computer Fraud and Abuse Act.
Those people should seek their own legal advice.
In cases like these, companies often try to go after the upstream project, not just operators. The law gives them lots of tools for this: the CFAA has a conspiracy provision; The DMCA has a provision against making software for circumventing copyright; Trademark law might make the name nitter or xcancel illegal; and finally even if the claims are weak the litigation itself is an enormous burden
I imagine it will be hosted in jurisdictions other than the US.
> Computer Fraud and Abuse Act
Meanwhile it's OK for OpenAI, Anthropic and Meta to hack companies all willy-nilly. Mad world!