Eh. Investors invest in lots of companies, some of which make pretty bad mistakes. I think Superfish should be forced to wither on the vine because of this - and especially because it pawned off responsibility by saying, "hey, it was those guys, not us!" as should Lenovo ("it is just theoretical!"), but I doubt the investors explicitly backed something with the intent to break security. Few do.
Few do, I can probably agree with that. But it's not like investors through money out of the window unknowingly of where it ends.
They either knew about it and didn't care about it or they just didn't care about it in any case, because following due diligence would've raised some red lights.
Most likely someone showed them some Powerpoint slides, and the hapless investors just did not understand that there could be serious privacy and security implications.
That doesn't mean they aren't responsible and shouldn't burn their fingers; investors actually should look into these things when they decide where to invest.