Sending data to Google, FaceBook and AppsFlyer (and other American companies) is generally legal under GDPR.
All three companies are covered under the US-EU Privacy Shield framework: https://www.privacyshield.gov/participant_search
Furthermore, sending PII data to a non-EU country is also allowed under GDPR as long as the company in question obeys the GDPR rules. Like I said, those rules are complex, and there could very well be some technical violations by TikTok, but that's not demonstrated here.
Browser/device fingerprinting for anti-fraud is a well established industry practice. Browser makers don't like this practice and have taken steps to make it harder, but the truth is that it's used across the industry.
The open source license violations could be actual civil, but not criminal, violations. TikTok does maintain a list of open source licenses here: https://www.tiktok.com/legal/open-source?lang=en It looks like it's only for its app and not its website though. Violations of the MIT/BSD license by using a npm package and forgetting to include it in the documentation, unfortunately is pretty common across the industry. That doesn't make it right, and we should hold big companies to a higher standard of compliance, but if anybody wanted to make a complaint it would have to be the copyright holder.
TL/DR: I don't think the author demonstrated anything illegal here or out of line with normal industry practice. You can argue about the morality of certain industry practices (like fingerprinting) but TikTok is far from an outlier here.