This is Apple's baseline anti-malware rule — any code that behaves like a virus, spyware, or unauthorized remote-access tool, even bundled inside an otherwise legitimate app, is an automatic rejection.
Almost always traced to a compromised or malicious third-party SDK pulled in through a dependency, rather than code the developer wrote themselves.
"Your app contains code designed to damage, disrupt, or gain unauthorized access to a device or network, per guideline 2.5.3."