Good question! Tripling the first block's size (12288=3x4096) happened the most recent commit, to make all of the Padmé sizes possible.
https://codeberg.org/markdascher/moochacha/commit/3145d7fb95...
The original encrypted format was more straightforward: 32 + 4112 + 4112 + ... + (last block, less than 4112) bytes. That initial 32-byte seed messed up the math just enough that a 2 MiB output was impossible. (It would require the last block be exactly 4112 bytes, which isn't allowed.)
If those extra 32 bytes weren't there, then it's a lot easier to calculate the impossible sizes, since they're just multiples of 4112. And those never collide with Padmé, at least for all 64-bit file sizes.
I like to think of that first block as 32+12288+16, getting block boundaries lined back up on even multiples of 4112.
Writing your own crypto for fun should be encuraged.