Apps flagged by Google Play Protect's automated scanning as containing malicious code, trojans, or exploit behavior are held regardless of intent — a legitimate SDK that behaves like known malware can trigger this.
A surprisingly common false-positive cause is an aggressive obfuscation/packing tool applied to the build, which shares behavioral signatures with actual malware packers.
"Google Play Protect detected code in your app that exhibits behavior consistent with malware, per the Malware policy. Your app has been suspended."