Having to pay money introduces a money-trail and a paper-trail. If a payment for a certificate is made with stolen CC details then the certificate gets revoked. This also effectively stops opportunistically-written malware taking advantage of current events (click bait email subject lines) to spread via email attachments.
The value from code-signing isn’t just the (I agree: very weak) attestation of the software’s author’s identity - but because it introduces a revocation mechanism and a reputation system - and creates barriers-to-entry that burden malware authors more than legitimate software vendors.
It’s not perfect, but don’t let perfect be the enemy of good.
Also remember that the only proven successful alternative to the current open PKI/CA system is the closed walled-garden approach favoured by Apple. I don’t think any Web-of-trust system has ever really been demonstrated as being feasible long-term without some WoT nodes evolving into pre-trusted/super-trusted nodes with the same power that CAs have today.
And at least with PKI+CAs you can add your own trusted root certificates and remove those you don’t trust.