The software project itself is probably fine, but the legal risk is always going to be with the person that hosts it with the intention of facilitating the unauthorized access of Twitter's website. Seems like that could run afoul of the Computer Fraud and Abuse Act.
Those people should seek their own legal advice.
Except this is settled case law. LinkedIn tried and lost against scrapers.
Host the infra in countries unfriendly to the US and its legal framework apparatus. Continually package the archive as torrents for distribution globally.
The project maintainer, Zedeus, runs the most or second-most popular instance, and I assume his lawyers decided that was okay.