Google deleted an app whose sole purpose for existing was misdirection (as described by the application's author), and which was already voluntarily withdrawn. The malware application has an attack vector that involves a remote site that wouldn't necessarily always be under the control of the original author.
I have a hard time feeling outraged about this; it seems like exactly the kind of reason why both Apple and Google added the ability to remotely remove applications to their marketplaces.
And, note that this kill-switch only applies to Market-supplied applications; if you install an APK yourself manually, they can't remove it. (In fact, installing or removing an app via the Market actually uses the intents for installing and removing applications that Google used here, rather than installing the APK directly.)