If an LLM model has been fed leaked code, then that is a general problem for that model and for its use for anything. Singling out its use for an open-source project and denouncing that as a potential problem while otherwise keeping quiet about it just makes no sense. Just take legal action against the model if there's anything plausible to warrant that, don't weaponize it against open-source projects.
With the project essentially implementing the entire API method by method, the chances of LLMs repeating some of the leaked source code would be tremendous.
A one-directional fork of ReactOS might be able to make some fast progress for a few people who desperately need certain programs to work, but I don't think the project will benefit from LLMs.
But, if any such model got fed with leaked code, then how is this a specific open-source project's problem and not of all projects (either open-source or private) that got to ever use that model?
Then, (having thought this just now) how can an argument relying on (legally) undisclosed information be used against anything public? Isn't the onus on the party having the undisclosed information to prove that it preceded the public one? How can that precedence be trusted by an independent judging party if the undisclosed information (source-code and systems managing that source code) is and always has been in the hands of the accusing (thus biased) party?