Someone who has a hard time getting market rates might not be as qualified to fix the software as they think they are.
Any suppositions as to why it would be deliberate?
/krazyconspiracy :-P
So implementing weak crypto dramatically lowers the risk of prosecution or worse for the attackers.
A reasonable Salsa20/20 implementation on a modest processor encrypts on the order of 400MiB/s [0][1]. So that the author went to the trouble of halving the number of rounds and changing the word-size when there are perfectly good and plenty fast off-the-shelf Salsa implementations strikes me as rather strange. Surely this is not the bottleneck on most employee's machines.
And then there's the apparently tiny keyspace used. You could argue that this makes the key more "user-friendly" (!), but just a hex representation of a random 256bit key would seem much more natural, and the poor targets are hardly in a position to complain.
[0] https://www.cryptopp.com/benchmarks.html [1] https://cr.yp.to/snuffle.html
Also, does it apply to the PHP/Perl world of malware, the kind that gets installed on cracked, old and weak WordPress sites? There's 20 variations of "Web Shell by oRb" floating around, for example, and many, many versions of Perl IRC bots, for example.