1. HideNoSeek is a novel and generic camouflage attack that evades detectors based on syntactic features without needing any information about the system it is trying to evade.

2. The attack consists of changing the constructs of malicious JavaScript samples to reproduce a benign syntax by automatically rewriting the Abstract Syntax Trees (ASTs) of malicious JavaScript inputs into existing benign ones.

3. In practice, HideNoSeek can produce on average 14 different malicious samples with the same AST as each Alexa top 10,000 web page, rendering targeted static detectors unreliable.

