Probably wrong to classify the manufacturer as malicious rather than the importer. Sounds like these units were brought to the US in violation of contractual agreements and thus were disabled when the manufacturer decided to enforce it.
It's likely they had no contractual agreement with the current owners of the inverters, and yet they have elected to wilfully damage the property of the current owners because they can.
Wilfully damaging someone else's property without permission of the current owner seems pretty malicious, regardless of whether the importers (or maybe someone who supplied to the importer) were in breach of a contract.
But regardless, they're clearly not owned by Deye any longer. Causing damage to an unrelated party in retaliation for a contract dispute between two manufacturers is not OK.
Deciding to enforce something like this after your product has already been sold/installed seems extremely dubious.
Even just building in the capability (assuming this wasn't installed via a generic software update, in which case I'd have some follow-up questions on the security against malware of these things) shows significant malicious intent.